Trust & EU hosting

Know what you are trusting.

Encryption is important. So is being clear about where the service runs, who helps deliver it, and what it cannot do.

The vault’s home

Helsinki, Finland.
European Union.

The PineKey application, primary vault database and routine server backups run on Hetzner infrastructure in Helsinki. The provider behind PineKey is a Swedish company.

Cloudflare provides global network delivery. Resend and MXroute handle service and support mail. Supporting processing can take place outside the EEA; “EU-hosted vault” does not mean every data flow stays in the EU.

Read the provider register →

Before storage

Encryption starts
on your device.

Your vault contents are encrypted on your device before reaching our servers. Your master password unlocks protected encryption keys locally and is not sent to the application API.

Our servers can read account email, organisation membership, permissions, timestamps and other service metadata needed to operate the service. A compromised device or unsafe sharing can expose information after it is decrypted.

See what data is processed →

Controls you can use today.

  • Authenticator-based two-factor sign-in
  • Automatic locking and revocable device sessions
  • Separate organisation keys and collection permissions
  • Password-encrypted export and content history
  • Prearranged, read-only emergency access

You choose who receives shared or emergency access. We cannot recover vault contents by resetting a forgotten master password.

Current limits, stated plainly.

PineKey is in invitation beta. Automated tests and restore checks support development, but an independent security audit or certification has not been completed. No uptime SLA is offered.

Routine backups are encrypted and stored on the hosting server. Automated offsite backup is not configured yet. Keep your own encrypted exports, especially for information you cannot replace.

An optional offline copy covers personal items only and must be refreshed within seven days. A disconnected device cannot receive an immediate revocation; already-copied secrets cannot be recalled.

Paperwork is part of the service.

Our DPA is available to organisations independently of the planned paid tier. Written confirmation identifies the customer, covered processing and provider arrangements before it takes effect.

Read and request the DPA →

Found a security issue?

Start with a private report to [email protected]. Describe the affected page and a minimal reproduction using your own test account. Ask for a suitable channel before sending sensitive evidence.

Do not access another person’s vault, copy their data, disrupt the service or publish live credentials. Stop testing if unexpected third-party data appears. No paid bug-bounty programme is currently offered.