Security

Protect the map.
Keep the keys elsewhere.

BitTwelve was built around a small recovery roadmap: where to look, who to contact, and what to do next. The safest map contains no passwords, wallet seeds, private keys, legal originals, or other access credentials.

Private development: the product interfaces are available as non-operational previews, while creation, word entry, recovery, updates, membership actions, email, and billing remain disabled server-side.
01

Minimize what you put in.

Use BitTwelve as a pointer system. Describe locations and order of operations without copying the underlying secrets into the map. Less sensitive content means less consequence if anything ever goes wrong.

02

Encryption begins on your device.

The recovery roadmap is encrypted in the browser with AES-256-GCM before the hosted encrypted package is stored. The twelve-word code is used locally to derive the encryption material and storage locator.

03

Twelve words. Never a wallet seed.

BitTwelve uses the familiar BIP39 English vocabulary but rejects generated twelve-word sequences that pass the BIP39 checksum. During recovery, a valid 12-word BIP39 wallet mnemonic is refused locally before a package request is made.

The recovery system does not need

your beneficiary account · your wallet seed · your password · your private key · your legal originals

04

Updates keep the same words.

Each update creates a new immutable encrypted version under the same recovery locator. A current-version manifest is authenticated with key material derived locally from the twelve words, so the client can reject an arbitrary substituted hosted envelope. Hosted infrastructure is still trusted for availability and freshness, which is why the independent offline recovery file remains important.

05

Membership and maps are separate.

The completed product design keeps membership identity separate from recovery data. When enabled, membership uses an email address and Stripe subscription record to authorize creation and hosted-map updates. The encrypted package is designed not to contain the membership email, payment card, or Stripe customer record, and the twelve-word code is not intended to be sent to Stripe or Resend.

06

Recovery is not behind a paywall.

The product was designed so opening an existing hosted BitTwelve would not require an active membership. The downloadable offline recovery file provides an independent path with no network connection capability. Operational recovery is currently disabled on the live site while the project is in private development.

07

Privacy is not anonymity.

Stripe, Resend, Cloudflare, your ISP, browsers, and other network infrastructure may process ordinary data required to provide payment, email, and website delivery. BitTwelve does not promise network anonymity.

08

Transparent by design. Still not magic.

BitTwelve explains how its recovery system is designed, what it is intended to protect, and its important limitations. The production source repository is private for now. Transparency is not a security guarantee: a compromised device, browser extension, software defect, malicious deployment, or future cryptographic weakness could still defeat the intended model. Keep independent recovery materials and test them.

The principle is simple.

Store the directions.
Keep the secrets yourself.

Project inquiries