Security
How Granite protects your notes, and what it does not do.
Encryption
- In transit: TLS 1.2 or newer everywhere, with HSTS.
- At rest: every vault has its own random 256-bit key. Files are encrypted with AES-256-GCM before they are written to disk. Vault keys are stored only wrapped by a key-encryption key: one for personal accounts and one per Business workspace, themselves wrapped by a master key that never enters the database or any backup.
- Sensitive fields such as two-step secrets, OAuth and SSO secrets, webhook secrets, comments, search passages, and co-editing history are encrypted in the application too.
- Deletion: deleting a vault removes its files and its key; deleting a workspace destroys its key, so nothing it held can be decrypted again.
Encryption is done by Granite's servers, not end to end. Search, the knowledge base for AI tools, and live co-editing need the server to read your notes. Your notes are never used to train AI models, and Granite has no AI assistant of its own.
Accounts and access
- Passwords are hashed with Argon2id. Two-step verification with an authenticator app and recovery codes.
- Sessions rotate their refresh tokens and end everywhere when you change your password or sign out all devices.
- API tokens and connected AI tools get only the scopes and vaults you choose, and you can revoke them at any time.
- Workspaces add single sign-on (SAML 2.0, OpenID Connect), SCIM provisioning, security policies, and an audit log.
Infrastructure
- Granite runs on a dedicated server; notes and attachments are stored on its disk, encrypted as above.
- Backups are encrypted before they leave the server and are kept in Amazon S3 (United States) for 35 days.
- Every request is checked against one authorization layer, and tenants are separated in the database with row-level security.
Your data
You can export every vault as plain files, export your whole account, and delete it. See the privacy policy and sub-processors.
Reporting a vulnerability
Email security@granite.md. Please give us a chance to fix the issue before sharing it publicly; we reply within two business days.