AES-256-GCM
Encryption
Authenticated symmetric encryption that uses a 256-bit AES key. Galois/Counter Mode protects confidentiality and detects tampering. AES-256 is considered resistant to known quantum attacks, but no cryptographic design can promise immunity from every future attack. PhantomVault's current design uses AES-256-GCM for Vault content and key wrapping.
See the PhantomVault design →
Apple silicon
Platform
Apple's M-series processors for Mac, built around the Arm architecture and Apple security hardware. The planned PhantomSecure suite requires macOS 27 or later on an Apple silicon Mac.
Argon2id
Encryption
A memory-hard password derivation function designed to make large-scale password guessing expensive. PhantomVault's current design uses Argon2id to derive passphrase-based unlock material.
See the PhantomVault design →
Deep packet inspection
Network
Examining network payloads as well as connection metadata when those payloads are visible to the inspecting system. It does not automatically reveal content protected by end-to-end encryption.
Learn about PhantomProtect →
DNS filtering
Network
Using domain-name requests and policy rules to block or redirect connections to selected domains. DNS filtering does not inspect a page's full content and cannot guarantee that every harmful connection will be stopped.
Learn about PhantomProtect →
DoD 5220.22-M
Secure deletion
An older overwrite procedure often cited by wiping tools. It is not a universal guarantee of data destruction and is not an appropriate proof of sanitization for every device, especially an SSD.
Learn about PhantomWipe →
FSKit
Platform
An Apple framework for building user-space file systems that integrate with macOS. PhantomVault's current design uses FSKit to present an unlocked Vault in Finder without a legacy kernel extension.
See the PhantomVault design →
Gutmann method
Secure deletion
A 35-pass overwrite method created for older magnetic-drive encoding schemes. More passes do not automatically provide better erasure, and this method was not designed for modern SSDs.
Learn about PhantomWipe →
HKDF
Encryption
An HMAC-based function for deriving purpose-specific cryptographic keys from existing key material and context. HKDF separates keys for different jobs, but it does not add entropy to weak input. PhantomVault's current design uses HKDF to derive the optional ML-KEM wrapping key.
See the PhantomVault design →
Hidden or decoy vault
Encryption
A design that presents alternate content while attempting not to reveal that other protected content exists. PhantomVault's decoy capability is planned for public launch and has not yet passed plausible-deniability validation.
See the PhantomVault launch plan →
ML-KEM-1024
Encryption
The highest-strength parameter set of the NIST-standardized Module-Lattice-Based Key-Encapsulation Mechanism in FIPS 203. It establishes a shared secret for key protection; it is not bulk file encryption. PhantomVault's optional Dual-Key Protection uses ML-KEM-1024 around its random master key.
See the PhantomVault design →
Network Extension
Network
A family of Apple frameworks for building VPNs, DNS proxies, content filters, and related network services under operating-system controls. The exact visibility and permissions depend on the extension type and user approval.
Learn about network protection →
Notarization
Platform
Apple's automated malware and signing check for software distributed outside the Mac App Store. Developers can attach the resulting ticket to an app, a process called stapling. Notarization is not a complete security audit.
On-device processing
Privacy
Performing a specific task locally on your Mac instead of sending that task's data to a remote service. It can reduce data exposure, but it does not mean an app never makes network requests for accounts, updates, threat intelligence, or user-approved telemetry.
Plausible deniability
Encryption
A threat-model-dependent property in which an observer lacks practical evidence that additional protected data exists. It must account for more than passwords, including file structure, timing, logs, Keychain artifacts, backups, mounting behavior, and errors. PhantomVault's planned decoy design is not yet verified to provide this property.
See the PhantomVault launch plan →
Post-quantum cryptography (PQC)
Encryption
Cryptography based on algorithms believed to resist known attacks by both conventional and quantum computers. PQC includes several types of tools. ML-KEM, for example, establishes a shared secret; it does not encrypt every file. "Post-quantum" describes the design goal, not a guarantee against every future technique.
See the PhantomVault design →
Secure deletion
Secure deletion
A sanitization outcome intended to prevent recovery. The correct method depends on the storage medium, file system, encryption, snapshots, and backups. Overwriting one file is not a reliable guarantee on every SSD because wear leveling can move physical writes.
Learn about PhantomWipe →
Secure Enclave
Platform
An isolated Apple security subsystem that can generate or use supported private keys without exposing ordinary key material to the main operating system. In PhantomVault's device-bound design, ML-KEM-1024 private-key operations occur in the Secure Enclave and a device-bound representation is kept in the local Keychain.
See the device-bound option →
Telemetry
Privacy
Product-use, performance, threat, or diagnostic information sent from software to its developer or service operator. PhantomSecure's planned release policy keeps optional telemetry off by default and requires an explicit opt-in before it is collected, staged, queued, or sent. Essential account, update, and threat-intelligence traffic is separate and will be disclosed separately.
TRIM
Secure deletion
A command that tells an SSD which logical blocks are no longer in use so its controller may reclaim them. TRIM does not prove when, or whether, every underlying physical cell has been erased.
Learn about PhantomWipe →
YARA-X
Network
A rule-matching engine used to identify files or data that match defined malware and threat patterns. Results depend on rule quality and coverage, so a clean result is not proof that a file is harmless.
Learn about PhantomProtect →
Zero-knowledge encryption
Privacy
An architecture in which a service operator lacks the key material needed to decrypt user content. The claim depends on the complete system, including recovery, backups, key synchronization, and support tools. It is not simply another name for on-device processing.
No terms match your search. Try a different word.