NAUTIQPricingSecurityFAQSign in

Built like a vault.
Only you hold the key.

Your documents are end-to-end encrypted on your device before they ever reach us — so we cannot read them, and neither can anyone else.

Zero-knowledge by design

NAUTIQ is a zero-knowledge vault. Your document files are encrypted on your own device and uploaded only as ciphertext. The keys that decrypt them never leave your devices and are never sent to our servers. This means that, by design, NAUTIQ cannot open your passport, your seaman’s book, your medical certificate, or any other file you store — and cannot hand a readable copy to anyone.

How encryption works

  • Documents are encrypted with AES-256-CBC and authenticated with Encrypt-then-HMAC-SHA256, so a file cannot be silently tampered with. Encryption happens on your device, before upload.
  • What is encrypted: the contents of every document and scan you store.
  • What is not encrypted: a small amount of operational metadata needed to run the service — your account email, document titles/dates you type into the form, timestamps, and billing identifiers. We keep this minimal.

Your keys, your control

A single random 256-bit data key encrypts your files. That key is itself wrapped (encrypted) by a key derived from your recovery code using PBKDF2-SHA256 with 600,000 iterations and a per-user random salt. The recovery code is generated on your device and is never transmitted to us. On a device that supports it, you can add a passkey / biometric unlock as a convenience — the underlying key stays on the device and is never shared.

Account recovery — and its honest trade-off

Because of this design, we cannot reset your password or recover your documents for you. If you lose your recovery code and access to all your signed-in devices, your documents cannot be recovered — by anyone, including us. This is the same property that stops anyone else from reading your files. Keep your recovery code somewhere safe and offline: a password manager, a printout, or a secure note.

What we can and cannot see

We cannot see

  • The contents of your documents or scans
  • Your encryption keys or recovery code

We can see

  • Your account email and a unique account ID
  • Document titles, dates and categories you type into the app
  • Timestamps and basic technical logs
  • Billing identifiers handled by the app stores

What NAUTIQ protects against — and what it doesn’t

NAUTIQ is built to protect you against a server breach, against us reading your data, and against interception while your files travel to the cloud. It cannot protect you against a compromised device, malware or a keylogger on your phone or computer, a weak or leaked recovery code, or losing your recovery code together with all your devices. Security is a shared responsibility — keep your devices and recovery code safe.

Hosting & data location

Encrypted documents, account data and sync run on Google Firebase / Google Cloud infrastructure. Because your files are encrypted before they reach Google, the storage provider only ever holds ciphertext. We are working to keep data processed within the EU where possible; the specific storage region and transfer safeguards are described in our Privacy Policy.

No tracking

NAUTIQ uses no third-party analytics, no advertising trackers and no marketing pixels. We do not sell or share your personal data. The only cookies we set are the strictly-necessary ones that keep you signed in.

Independent verification

We do not currently hold formal certifications such as SOC 2 or ISO 27001, and we will not imply that we do. We are committed to commissioning an independent security and cryptography review and will publish the results here when available.

Responsible disclosure

If you believe you have found a security vulnerability, please email security@nautiq-doc.com. We welcome good-faith research, will not pursue researchers who act responsibly, and aim to acknowledge reports promptly.

Service providers

NAUTIQ relies on a small set of providers to operate. Each only ever receives the data it needs, and your document contents remain encrypted and unreadable to them:

  • Google (Firebase & Google Cloud, Vertex AI) — authentication, encrypted storage, hosting, and AI features.
  • Cloudflare — bot/abuse protection (Turnstile).
  • Resend — transactional email (expiry reminders); reminders carry only a document name and date, never contents.
  • Apple App Store / Google Play — app distribution and in-app billing.

If something goes wrong

In the event of a personal-data breach affecting you, we will investigate promptly and notify affected users and any relevant authorities as required by law. Because your documents are end-to-end encrypted, a breach of our storage would expose ciphertext, not your readable files.

© 2026 NAUTIQ · Privacy · Terms · FAQ

© 2026 NAUTIQ · contact@nautiq-doc.com