Enterprise-grade cryptographic security.
Reminda is engineered with zero-knowledge architecture. Your knowledge vault is encrypted locally on your device — strictly private to you.
Built for absolute confidentiality
Client-Side AES-256-GCM Encryption
All notes, flashcards, and AI memory tags are encrypted locally on your device before reaching the cloud. Plaintext never leaves your hardware.
Zero-Knowledge Key Architecture
Your master passphrase derives cryptographic keys locally using PBKDF2 with SHA-256. Reminda servers hold zero access to your decryption keys.
Cloudflare Turnstile & DDoS Defense
Integrated Cloudflare Turnstile bot protection ensures zero automated attacks without frustrating user CAPTCHAs.
Google Secret Manager & Encrypted DB
Infrastructure secrets are automatically rotated via Google Secret Manager. PostgreSQL databases feature AES-256 encryption at rest.
Compliance & Verification
| Standard | Status | Scope | Verification |
|---|---|---|---|
| SOC 2 Type II | Architecture Aligned | Security, Confidentiality & Availability | Design Principles |
| ISO/IEC 27001 | Design Principles | Information Security Management System (ISMS) | Continuous Monitoring |
| GDPR (EU) | Full Compliance | Zero Data Mining & Right to Complete Erasure | Ongoing |
| CCPA (California) | Full Compliance | Consumer Data Privacy & Zero Data Selling | Ongoing |
Found a potential vulnerability?
We maintain a zero-tolerance policy for security exploits. If you discover a vulnerability, please disclose it responsibly to our security engineering team.