Possessions · LIGHT AND DARK ENERGY LTD
Security at Possessions
Possessions reduces the amount of public identity it asks for and separates protected notes from operational portfolio data. No online service can promise absolute security.
What is encrypted in the browser
Private Vault notes, protected exact coordinates, attachment names and attachment contents are encrypted before transmission. Every attachment receives its own random file key; that key is protected by the vault key. The vault key is wrapped using keys derived from the Master Secret and Recovery Key. Possessions does not store either secret in readable form.
What the service must process
Quantum ID, encrypted envelopes, account status, sessions, asset names and types, selected map display coordinates, values, obligations, cash-flow entries, occupancy dates, attachment size and upload time, and security events are processed to operate the service. Do not assume every field is end-to-end encrypted.
The map interface code is served directly by Possessions. No third-party JavaScript is permitted inside the private vault. OpenStreetMap tile requests remain necessary to draw the map and can disclose ordinary network information to the tile service.
Documents and photos
Early Access attachments are stored as encrypted data in private service storage, never in the public website directory. The service cannot ordinarily read their names or contents. PDF, JPEG, PNG and WebP are accepted up to 5 MB. Files are downloaded rather than executed inside the service.
Rights, distinctions and unusual titles
You may record documentary evidence for a barony, manorial title, hereditary or contractual right, honorary distinction or micronational designation. Possessions does not determine whether an item is legally recognised, transferable, inheritable or valuable. Keep the claimed status, relevant jurisdiction, issuing or recognising authority and source documents explicit.
Your security responsibilities
- Use a unique Master Secret and do not reuse a password.
- Keep the Recovery Key offline and separate.
- Lock the vault on shared devices.
- Use Private Vault only for sensitive details and consider whether storing a critical safe combination online is appropriate for your risk profile.
Residual risk
Compromised devices, browser extensions, screenshots, leaked keys, malicious imports, software vulnerabilities and compelled legal disclosure can still create risk. Encryption reduces risk; it does not remove it.
Report a security concern
Email contact@lightanddarkenergy.uk with the subject “Possessions security”. Do not include secrets or precise locations.