Enter the black

Privacy is not a feature.
It's the architecture.

BLKH01E is a private digital environment, an app designed to protect the data, conversations and information that matter most.

Scroll to enter
Inside the app

See it up close.

An OLED-first graphical interface, designed to be direct, discreet and efficient.

  • BLKH01E lock screen with numeric passcode entry
  • Encrypted vault home, drawers for photos, audio, documents, passwords, links and contacts
  • Encryption tool, encrypt a message or file with a password
  • Private browser, an ephemeral browsing session
  • Settings, passcode, recovery phrase, decoy vault and protection options
Swipe to explore

YOUR DATA.
YOUR KEYS.
YOUR UNIVERSE.

Privacy should not be an afterthought. It should be the starting point. BLKH01E was created to give you greater control over the information that matters most.

How hard is it to break BLKH01E?

Much harder than you think.

With the right settings, the encryption is designed to be computationally infeasible to break by brute force with current technology.

  1. PASSWORD
  2. ARGON2ID
    hardened derivation
  3. MASTER KEY
  4. DEVICE PROTECTION
  5. UNIQUE FILE KEYS
  6. ENCRYPTED DATA

An attacker does not face one barrier.
They face layers.

This is not a password on a folder. It's layers of protection stacked on top of each other, and defeating one only reveals the next. Compromising a single point doesn't hand over the rest; it forces the attacker to start over, again and again.

What does "secure" really mean?

256-bit encryption.

A key space so vast that brute force runs out of time before it runs out of guesses.

Key space
2256
0.000000000 × 1077
Possible key combinations

The number of possible combinations is so large that exhaustive brute-force search is not considered practically feasible with current technology when strong cryptographic keys are properly generated and protected.

Your password is not your data.

And your password is not your key.

The password is not used as a simple direct encryption key for every file. BLKH01E uses a layered key architecture designed to separate authentication, key derivation and data encryption.

  1. PASSWORD
  2. ARGON2ID
  3. MASTER KEY
  4. FILE ENCRYPTION KEY
  5. ENCRYPTED FILE

One file.
One key.

Per-item encryption keys are designed to limit the impact of a compromised individual key.

Built around modern cryptography

State-of-the-art cryptography.

The same modern primitives that secure TLS 1.3, WireGuard and today's most trusted secure messaging, not home-grown algorithms, but the cryptography the world already relies on, wrapped in a layered key architecture.

Argon2id
Password-based key derivation

Memory-hard derivation designed to increase the cost of brute-force attacks.

ChaCha20-Poly1305
Authenticated encryption

Protects data confidentiality and integrity together.

X25519
Key agreement

Modern elliptic-curve key agreement for establishing shared secrets.

HKDF
Key derivation & separation

Derives distinct keys from shared secret material.

HMAC-SHA256
Message authentication

Verifies message integrity and authenticity.

SHA-256
Cryptographic hashing

One-way hashing for integrity and fingerprints.

The security gap

Not all security is created equal.

The comparison is not that other apps are unsafe. It is a difference in architecture, where your private data lives, and how it is protected.

Ordinary apps
  • Password-only protection
  • Centralized infrastructure
  • Server-side dependencies
  • Data collection may be part of the business model
  • Large centralized attack surfaces
  • Private content held on shared servers
  • Local-first architecture
  • Modern cryptographic primitives
  • Device-bound key protection
  • Per-item encryption keys
  • Privacy-focused design
  • No central repository for private vault contents

Built to protect data.
Not to collect it.

Privacy by design

Privacy is not a feature.
It's the architecture.

LOCAL FIRST

Prioritize local processing and local protection where possible.

MINIMIZED DATA EXPOSURE

Reduce unnecessary exposure of private content.

NO CENTRAL PRIVATE DATA REPOSITORY

The core architecture does not rely on a central server storing the user's private vault contents.

USER CONTROL

Keep the user in control of their private data and credentials.

Metadata can still exist. Networks, operating systems and third-party services may observe certain information depending on how they are used. BLKH01E is designed to minimize exposure, not to claim that nothing can ever be observed.

What if someone really wants your data?

Really.

The strongest security model is not the one that claims nobody can attack it. It is the one that makes unauthorized access technically difficult and minimizes what an attacker can obtain from any single point of compromise.

NO CENTRAL PRIVATE DATABASE.

NO MASTER PASSWORD STORED ON OUR SERVERS.

NO SINGLE SERVER HOLDING YOUR PRIVATE WORLD.

NO CENTRAL REPOSITORY OF YOUR VAULT CONTENT.

Even a highly capable adversary cannot simply request private vault contents from a server that does not possess them.

No cryptographic system can protect data that is exposed on a compromised device while actively being used.

Designed for adversaries with resources

Built for the hard cases.

BLKH01E is designed to make unauthorized access difficult even when an attacker has significant resources.

LOST DEVICE

Protected data remains encrypted.

STOLEN STORAGE

Encrypted data is designed to remain unusable without the required keys.

PASSWORD GUESSING

Password-derived keys are hardened using Argon2id.

SERVER BREACH

The BLKH01E core does not maintain a central private vault database.

MESSAGE INTERCEPTION

Encrypted communication is designed to protect message content in transit.

Private messages. Not private because we say so.

Private by architecture.

BLKH01E communication is designed around end-to-end encryption and modern secure messaging principles.

  1. YOUR DEVICE
  2. ENCRYPTED
    before it leaves
  3. RELAY
    transport only
  4. ENCRYPTED
    in transit
  5. RECIPIENT

The relay carries the message.
It doesn't hold the key.

The relay acts as a transport layer. Message content is encrypted before it leaves the sender's device and is decrypted by the intended recipient. Built around a Double Ratchet-based messaging architecture designed to provide forward secrecy and post-compromise recovery.

Transport services may still observe certain metadata such as network addresses or connection timing, depending on the transport architecture.

  • FORWARD SECRECYarchitecture
  • POST-COMPROMISE RECOVERYarchitecture
  • MESSAGE AUTHENTICATIONarchitecture
  • REPLAY PROTECTIONarchitecture
  • CONTACT VERIFICATIONarchitecture
Encrypt before you share

Not everything needs to travel in plaintext.

Encrypt messages and files before sharing them through the channels you already use.

  1. YOUR FILE
  2. ENCRYPT
  3. SHARE
  4. RECIPIENT
  5. DECRYPT
PlaintextChaCha20-Poly1305 · illustrative

Meet me at the usual place. 21:00.

Visual demonstration only. No real secrets are processed.

Cryptographic erasure

Delete the key.
Delete the access.

BLKH01E uses cryptographic deletion for protected content.

  1. ENCRYPTED DATA
  2. KEY DESTROYED
  3. ACCESS LOST

When the encryption key protecting an item is destroyed, the encrypted content can no longer be decrypted through that key.

This is key destruction, not a guarantee of physical overwrite on flash storage, and not a claim that every forensic trace is physically destroyed.

Alternate vault

One device.
More than one world.

Maintain an alternate private space protected by a separate credential, designed for privacy, separation and personal context.

VAULT A
PRIVATE SPACE
separate credential
VAULT B
ALTERNATE SPACE
separate credential
Private browser

A private session.
A clean exit.

Browse inside an ephemeral session designed to minimize locally retained browsing history.

  1. OPEN SESSION
  2. BROWSE
  3. CLOSE SESSION
  4. LOCAL SESSION DATA CLEARED

Private inside the application. This does not provide anonymity on the internet. ISPs, websites and networks may still observe activity depending on the connection.

Private AI

An AI that reads everything.
And tells no one.

BLKH01E uses Apple's on-device foundation models to search and summarize what is inside your vault. Inference runs on the iPhone's Neural Engine. No network call, no external AI API, no training on your data.

PRIVATE SEARCH

Reads text in photos (OCR), PDFs and documents, and transcribes audio, all on the device. Find items by what is inside them, not just by name.

SEMANTIC SEARCH

Ask for "rent receipt" and find it even when those words are not in the file name. Search by meaning, computed locally.

AI SUMMARIES

Summarize notes and documents with the on-device model. The summary is displayed and discarded, never stored, never sent.

  1. UNLOCKED VAULT
  2. ON-DEVICE MODEL
    Neural Engine
  3. RESULT DISPLAYED
  4. DISCARDED

Turn off the internet. It keeps working.

The AI only sees what you have already unlocked. It works on content decrypted in memory while the vault is open, writes nothing new to disk and sends nothing anywhere. Cloud AI does the opposite, your data becomes input on someone else's server.

Requires a device with Apple Intelligence. On devices without it, the feature simply does not exist, and core search does not depend on it.

Password health

Weak, reused, leaked.
Flagged without exposing you.

BLKH01E flags weak and reused passwords locally, and can check known breaches without ever sending your password. Store a strong one and fill it anywhere with AutoFill, straight from the vault.

WEAK & REUSED

Detected entirely on the device. No list of your accounts ever leaves the vault.

BREACH ALERT

Opt-in check against known leaks using k-anonymity. Only 5 characters of a hash are sent, never the password.

GENERATE & AUTOFILL

Generate a strong replacement, keep it in the vault and fill it in iOS apps and websites with AutoFill.

  1. YOUR PASSWORD
    never leaves the device
  2. HASHED ON DEVICE
  3. 5 HASH CHARACTERS SENT
    k-anonymity
  4. CANDIDATE LIST RETURNED
  5. MATCHED ON DEVICE

The breach check is opt-in. Weak and reused detection runs entirely on the device.

Everything private. One universe.

The BLKH01E universe.

A vault is just one part of it. Encryption, messaging, browsing, files, notes, passwords, wallets, contacts and on-device AI share a single private environment.

VAULT

Encrypted storage for the data that matters.

CHAT

End-to-end encrypted private messaging.

ENCRYPTION

Encrypt text and files before you share them.

BROWSER

Ephemeral, private browsing sessions.

NOTES

Private notes, encrypted at rest.

PASSWORDS

Credentials behind device-bound protection.

FILES

Documents sealed with per-item keys.

WALLETS

Seed phrases and keys, encrypted, with a receive QR.

CONTACTS

Contact details kept inside your universe.

PRIVATE AI

On-device search and summaries. Nothing leaves the phone.

Privacy architecture

Privacy by design.

DATA EXPOSUREMINIMIZED
LOCAL PROCESSINGPRIORITIZED
CENTRAL PRIVATE DATA STORAGENONE
USER CONTROLMAXIMIZED
TELEMETRYMINIMIZED
AI PROCESSINGON-DEVICE

What goes into BLKH01E
stays out of sight.

Photos. Documents. Messages. Passwords. Audio. Files. Your private digital life.

Your private universe.

You don't need to be a target
to value privacy.

Privacy is not paranoia.

It is control.

It is freedom.

It is the right to decide who gets access to your digital life.

Your private universe.

Your data.

Your keys.

Your control.