Sona security

Built to stay safe for a lifetime - even against a quantum computer

A digital twin is meant to last decades. So we did not protect it with encryption that is only "good enough for now." We protect it with encryption designed for the next era of computing.

What "quantum-safe" means, in plain English

Most of the encryption that protects the internet today could one day be broken by a powerful enough quantum computer. Experts widely expect such machines to arrive, and bad actors already follow a "harvest now, decrypt later" approach - stealing encrypted data today to unlock it once the technology exists.

Your twin is the most personal data you will ever create, and you intend to keep it for a lifetime. So we lock it with a new kind of encryption built specifically to resist quantum attacks. In one line: it is a lock designed so that even tomorrow's most powerful machine cannot pick it.

How the Sona Vault actually works

Sona Vault.

The post-quantum safe for your persona: NIST-standardized algorithms - ML-KEM (formerly Kyber) for key encapsulation, ML-DSA (formerly Dilithium) for signatures - with the keys held by you, on a horizon of decades.

Defense in depth.

PQC sits alongside strong, conventional encryption in transit (TLS) and at rest, plus data isolation between tenants and accounts. We apply standards designed for exactly this threat - now, not after old encryption becomes a liability.

Signed Persona: provenance and anti-deepfake.

Every byte your twin generates is cryptographically signed, so it can always be verified as a Sona twin and never passed off as the live person. In a world filling up with deepfakes, a signed persona is the currency of trust.

Privacy Edge.

The sensitive parts run on your device where possible - wake-word detection, a local persona cache - so privacy is a property of the architecture, not a policy promise.

NIST ML-KEMNIST ML-DSAGDPREU AI ActEncrypted in transit & at rest

Beyond encryption: the Trust Layer

Kill Switch.

Full export and irreversible deletion of your twin in one tap - always free. That is a public promise of the brand.

Consent Registry.

A twin can only be created by the verified person it represents, and the registry records who may do what with it, on what terms - revocable in one tap.

Continuation Plan.

Only the owner decides the twin's future: to whom, when, and how much ever opens - with triggers, verification, and family governance.

Anti-Dependency Design.

The twin points you back to living people and a living life. It is honest about what it is: "I am a model, not a consciousness."

Regulation, handled.

GDPR and EU AI Act aligned, with clear AI labeling. Legal review before launch in each market.

Security FAQ

What is post-quantum encryption in plain English?
It is encryption built to stay unbreakable even by future quantum computers, which could crack much of today's encryption. Sona uses it to protect your twin for the long term.
Is my twin really protected against quantum attacks?
The Vault uses NIST-standardized post-quantum algorithms (ML-KEM and ML-DSA) together with strong conventional encryption. That is the current state of the art for long-term data protection.
Can someone make a deepfake of me with Sona?
No. You can only build a twin of yourself, as a verified person, and everything it produces is signed and labeled as a Sona twin. That signature is what makes impersonation detectable.
What happens to my twin if I die?
Nothing you did not choose. Inheritance only happens on terms you set in advance, with verification and care designed in. By default, control stays locked to your wishes.

Become the second version of yourself

Sona is launching soon. Join the waitlist to be first to build your twin - and to own it, forever.