Sona security
Built to stay safe for a lifetime, even against a quantum computer
A digital twin is meant to last decades, so we did not protect it with encryption that is only good enough for now. We protect it with encryption designed for the next era of computing.
What "quantum-safe" means, in plain English
Most of the encryption that protects the internet today could one day be broken by a powerful enough quantum computer. NIST finalized new post-quantum standards in 2024 for exactly this reason. Meanwhile, bad actors already work on a "harvest now, decrypt later" basis: stealing encrypted data today so they can open it once the technology exists.
Your twin is the most personal data you will ever create, and you intend to keep it for a lifetime. So we lock it with encryption built specifically to resist quantum attacks: a lock designed so that even tomorrow's most powerful machine cannot pick it.
How the Sona Vault actually works
Sona Vault.
The post-quantum safe for your persona, built on all three NIST standards. ML-KEM (formerly Kyber) for key encapsulation, ML-DSA (formerly Dilithium) for signatures, and SLH-DSA (formerly SPHINCS+) as a second signature scheme on completely different mathematics, so a break in one does not take the other with it. The keys are held by you, on a horizon of decades.
Defense in depth.
Post-quantum cryptography sits alongside strong conventional encryption in transit (TLS) and at rest, plus data isolation between tenants and accounts. We are applying the standards built for exactly this threat now, rather than after old encryption becomes a liability.
Signed Persona: provenance and anti-deepfake.
Every byte your twin generates is cryptographically signed, so anyone can verify it came from a Sona twin and nobody can pass it off as the live person. In a world filling up with deepfakes, that signature is what makes a fake detectable.
Privacy Edge.
The sensitive parts run on your device where possible: wake-word detection and a local persona cache. Privacy holds because of how the system is built, not because we promise it in a policy.
Beyond encryption: the Trust Layer
Kill Switch.
Full export and irreversible deletion of your twin in one tap, always free. That is a public promise, not a setting we can quietly change.
Consent Registry.
A twin can only be created by the verified person it represents. The registry records who may do what with it and on what terms, and you can revoke any of it in one tap.
Continuation Plan.
Only the owner decides the twin's future: who gets access, when, and how much. Triggers, verification, and family governance are all set in advance by them.
Anti-Dependency Design.
The twin points you back to living people and a living life. It is honest about what it is: "I am a model, not a consciousness."
Regulation, handled.
GDPR, CCPA, and EU AI Act aligned, with clear AI labeling. Legal review before launch in each market.
Security FAQ
- What is post-quantum encryption in plain English?
- It is encryption built to stay unbreakable even by future quantum computers, which could crack much of today's encryption. Sona uses it to protect your twin for the long term.
- Is my twin protected against quantum attacks?
- Sona Vault uses all three NIST-standardized post-quantum algorithms (ML-KEM, ML-DSA, and SLH-DSA) together with strong conventional encryption. That is the current state of the art for long-term data protection, and we will move as the standards move.
- Can someone make a deepfake of me with Sona?
- No. You can only build a twin of yourself, as a verified person, and everything it produces is signed and labeled as a Sona twin. That signature is what makes impersonation detectable.
- What happens to my twin if I die?
- Nothing you did not choose. Inheritance only happens on terms you set in advance, with verification built in. If you set no terms, nothing opens to anyone.
Become the second version of yourself
Join the waitlist and be among the first to build your twin. You will own it, and one tap deletes it.