> For the complete documentation index, see [llms.txt](https://vector-privacy.gitbook.io/vector-privacy/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://vector-privacy.gitbook.io/vector-privacy/vector-messenger/intro/security.md).

# Security

Security Features & Design

Vector is designed to be as lean and frictionless as possible, without compromising on privacy or security. Too often, users are forced to choose between the two, with secure tools demanding technical knowledge and convenient tools quietly giving up privacy. Vector aims to bridge that gap by letting the complex backend handle the private and secure infrastructure while the user gets a simple, familiar experience. To support that goal, Vector is under constant internal auditing to identify areas that can be optimized and improved.

To learn more, visit: [Privacy](/vector-privacy/vector-messenger/intro/privacy.md), [Encryption](/vector-privacy/vector-messenger/intro/encryption.md), [Settings](/vector-privacy/vector-messenger/features/settings.md#security)

***

## Memory Hardening

In Vector, your private key never exists as one thing. It's split into four shares, hidden among hundreds of thousands of indistinguishable decoys, and only assembled on your device for microseconds during a signing operation, then wiped with volatile writes. When a forensic tool dumps your phone's memory, it doesn't find a key. It finds a sea of 32-byte blobs that all look exactly like one, and none of them are. Your messages stay yours, even after your phone leaves your hands. [Learn more](https://vectorapp.io/blog/memory-hardening/)

##

## Features

### Remote Signing

#### Amber Signing (Android)

Amber is a separate Android app that stores your Nostr private key and signs events on your behalf, following the NIP-55 standard. When paired with Vector, your nsec stays inside Amber and never touches the Vector app at all. Instead of holding your key directly, Vector sends signature requests to Amber, which handles them and returns only the signed result. This is the most secure option available on Android, since a compromise of Vector alone would not expose your private key.

***

#### Biometric Unlock (Android)

Biometric Unlock lets you protect your Vector account using your phone's built-in lock screen, whether that is a fingerprint, face unlock, PIN, or pattern. Once enabled, Vector will require authentication before your account can be accessed. Because it relies on your device's native authentication system, your biometric data never leaves your phone and is never accessible to Vector.

***

#### Changing Your Encryption Password

If you use a PIN or password for local encryption, you can change it at any time from Settings, and Vector will re-encrypt all of your local data with the new credential, including your Community data. Make sure to back up your new PIN or password before proceeding, as losing it means losing access to your encrypted data with no recovery method available.
