Security built around privacy

SecureRing's job is to make impersonation hard. Our architecture's job is to make sure we never hold more than we need.

Your device controls the keys

SecureRing's verification keys are generated on your device using Ed25519, a modern digital-signature scheme. Your private key is never transmitted to SecureRing — we only ever see your public key, which is safe to share and useless for impersonating you. Your private key is stored in your device's secure enclave or keychain (and on iOS may sync via iCloud Keychain to your other Apple devices).

This means there is no central database of private keys for an attacker to steal. The thing that lets someone verify as you — your private key — is held in your device's keychain, not on our servers. (On iOS, your key may sync through iCloud Keychain to your other Apple devices, so protecting your iCloud account is part of protecting your verification identity.)

Rotating safe words

The safe word shown on a verified call isn't a password you memorize. It's a rotating code computed on your device (HMAC-SHA256) that changes automatically every 30 seconds, so each verification uses a fresh value. There's nothing to forget and nothing to leak in a text message — and because the code rotates, one that's been overheard or recorded can't simply be replayed later.

What we don't store

What we do hold (the minimum)

All data is encrypted in transit and at rest, and retained only as long as needed or required by law. See the privacy policy for the full list.

How we differ from AI companies

Many services collect conversations and behavior to train models. SecureRing does the opposite: we collect too little to train on, we never sell data, and we never use your data for advertising. Our product is verification, not surveillance.

Service providers we rely on

A few features depend on third-party infrastructure: video calls (Twilio), push notifications (Apple APNs / Google Firebase), and encrypted database storage (Supabase). Each is used under its own terms for the narrow function it performs — e.g., Twilio carries call streams in transit only and doesn't store content for us. See the privacy policy for the full sub-processor list.

Honest limits

No verification system is foolproof. SecureRing confirms that a caller's paired device held a valid shared key at the moment of verification — it does not confirm intent, truthfulness, or that the device hasn't been compromised. SecureRing is a supplemental aid, not a guarantee and not a substitute for emergency services or your own judgment. Always verify another way if anything feels wrong.