How Merka Vault Keeps Your Data Yours
Security write-ups usually fail in one of two ways. Some hand-wave: “your data is safe with us.” Others bury the trust decision under a pile of technical specs. We want to do better than both. The question that matters is simple: who can read your data, and what do you have to believe for the answer to be “only you”?
Merka Vault handles personal data, family memories, identity, recovery, and eventually multi-user access. So a normal household must understand the security model, and the model must survive real scrutiny. Here it is.
The keys stay with you. This is the root of everything. Merka lets Cosmic Rocks support the service without custody of your data. Merka encrypts backups before they leave your control, so storage providers only hold ciphertext they cannot read. Support works without a back door into your vault. The goal is not “trust us.” The goal is to make you trust us less.
Your identity and your recovery plan are yours. A security model that depends on good company behavior forever is not a security model.
Native apps are the foundation, across iOS, Android, macOS, Windows, and Linux. That choice shrinks the attack surface. Browsers are good at many things. They are also general-purpose machines built to render any website on the internet. That is the wrong foundation for the most sensitive data you own. Native apps use platform security features and local device identity, which gives sensitive operations firmer ground.
The free tier runs the same model. It uses the same identity approach and the same native apps as the hardware versions. You can understand the trust story before you spend anything. A move to always-on hardware strengthens the boundaries further, because the system can assume more about the environment it runs in.
Multi-user access depends on hardware, on purpose. Data for several people raises the stakes well beyond a solo trial. When you add a spouse or a recovery contact, the product must get several people and several devices right at once. So shared access only ships on supported hardware that matches the required protection level. Laptop evaluation stays single-user. Dedicated machines unlock multi-user access once the foundation is strong enough. If the hardware cannot support it safely, the answer is no.
That slows our roadmap. It is still the right call for life-level data.
We design recovery around failure. Hardware breaks. Houses flood. Devices disappear. Companies change direction and services close. The design assumes all of it.
Backups are encrypted and provider-neutral, and Cosmic Rocks supports recovery without becoming the only route to it. The test we hold ourselves to: if your original hardware is gone, can you get your data back without giving custody to anyone? The answer must be yes.
We do not claim perfection. You still own real tradeoffs. Where the software runs. When hardware is worth it. How much backup you want. How carefully you guard your recovery materials.
The claim is narrower and more useful. You can start without a hardware purchase. Your keys do not live with providers. Native apps replace browser-only layers. Hardware arrives when always-on protection matters. Encrypted backups let you recover without any single company.
That is how your data stays yours. Not because we promised, but because the design leaves us no other option.