VaultMyPhone is built so the mobile app talks to your VaultMyPhone server, not directly to permanent infrastructure credentials.
Backup objects use AES-256-GCM encryption before they are uploaded. Integrity metadata is calculated for encrypted objects.
The server issues short-lived signed upload/restore URLs. Permanent object-storage secrets stay on the server.
The Android app requires customers to save and confirm their recovery key before encrypted backups begin.
The mobile app can require biometric or device-credential authentication before opening backup and recovery settings.
Customers can revoke a registered device, invalidate its API sessions and stop backup access from that device.
VaultMyPhone provides both in-app deletion requests and a public web deletion resource.