Han Lu

Security & Trust

Security is treated as a foundational requirement of Han Lu, not an optional layer.

Hardware Authentication

All authenticated accounts require hardware security keys (WebAuthn / FIDO2). Password-based authentication is not used.

Encryption

Sensitive records (notes, credentials, and designated data) use end-to-end encryption. Zero-knowledge design is applied where appropriate so that content remains inaccessible without the user’s keys.

Guest Portals

Guest access operates under independent encryption contexts. Each portal is strictly scoped, time-controllable, and immediately revocable by the creating member.

Access Codes

Two-word access codes grant visibility solely to the resources explicitly attached to them. They do not provide broader account access.