Uncompromising Security
Military-Grade Cryptographic Vault
Your secrets never touch disk in plaintext. Horizon's vault engine applies
AES-256-GCM authenticated encryption with a PBKDF2-SHA256 key derivation
function at 210,000 iterations — well above NIST and OWASP recommendations.
AES-256-GCM
Authenticated encryption with built-in integrity verification for every stored secret.
210,000 PBKDF2 Iterations
Key stretching far exceeds industry standard requirements, making brute-force attacks computationally infeasible.
Independent Master Key
Vault credentials are fully decoupled from login passwords — changing your account password never exposes secrets.
Zero-Downtime Key Rotation
Rotate master passphrases at any time. Horizon decrypts and re-encrypts all secrets in-memory with zero data loss.