WAYFARER GUIDE
Understand what protects your data
Practical guidance for the current beta, with clear choices and honest limitations.
Encrypted connections
HTTPS protects supported web connections and account traffic. The address bar only shows SECURE after a successful HTTPS navigation. This describes the connection, not whether a website is trustworthy. HTTP is labeled unencrypted.
Account access
Email verification codes are short-lived and limited against abuse. Secure, HttpOnly, SameSite cookies remember website sessions. Protect your email account and sign out on shared devices. Remove unfamiliar device sessions in My Account.
Vault encryption
Vault contents are encrypted locally with AES-256-GCM. PBKDF2-SHA256 with 600,000 iterations derives the key from your master passphrase. The server stores the encrypted envelope. This beta has not received an independent security audit. Encryption cannot protect a compromised device or maliciously altered website code.
Protection controls
Built-in ad and tracker filtering and cookie-notice hiding can be disabled globally or for a site. Hiding a notice does not make a consent choice. Filters cannot guarantee every unwanted request is blocked.
Current limitations
The Windows portable beta is unsigned. Website camera, microphone and location permissions are disabled. Chrome Web Store extensions are unsupported. Profiles are not end-to-end encrypted; vault data is separate. Update ZIPs are verified but require manual extraction.
Report a problem
Use Settings > Beta feedback to prepare a readable report you review and send through your mail app. Automatic capture stays local until you choose to share it. Never include passwords, verification codes or vault passphrases.
My Account Browse feature help