Atomics
Account Plans Usage Billing
Appearance
Language
English español España español Latinoamérica

Install Atomics App State Get help Share feedback Privacy Policy Terms of Service Sign out
© 2024-2026 Keith Andre Rose

How locking works

Lock a card with a passphrase and it’s scrambled in your browser before it’s saved. We store only the scrambled version and can’t open it with anything we keep. Here is what that protects, and what it doesn’t.

What you can lock

  • One note or one file at a time, up to 20 MB.
  • Select it, choose Lock… from the right-click menu or ⌘K, then Encrypt with a passphrase.
  • Rooms, whole spaces and other kinds of card can’t be locked yet.

What it protects

  • What’s inside. A note’s words and a file’s bytes are scrambled under a key made from your passphrase, on your device.
  • Who can change it. Only someone who has unlocked it can change what it holds, its hint or its lock, or take the lock off. Locking it gives us a fingerprint of a key only your passphrase, or a passkey you add, leads to, and we turn away any of those changes that doesn’t come with that key.
  • Your passphrase. It and the key never leave your browser, and we never receive either. If your browser offers to save the passphrase, its password manager keeps it, wherever that syncs.
  • The copies made from it. Search keeps only the card’s name. The space’s picture and its PNG, SVG and PDF exports draw a lock in its place, a zip leaves it out, a .space file carries it still scrambled, and the assistant can’t read what’s inside.
  • Other people’s windows. Unlocking opens it in your window only. Lock now, leaving the space or closing the page forgets the key, and everyone else sees the lock throughout.

What it doesn’t protect

  • What shows on the outside. The name, the hint, the kind of card, its size, where it sits, when it changed, and who locked it and last edited it. Anyone who can see the space sees those. A note takes its first line as its name while you write, so check the name before you lock it, and keep secrets out of the hint.
  • Guessing. Anyone who can see the space can copy the scrambled version and try passphrases on their own computers, as fast as they can, with nothing to stop them. A short passphrase falls quickly. Four or more unrelated words hold out far longer.
  • What was there before the lock. Anything that read the card before you locked it keeps what it read. In a synced space its contents reached our servers, and our storage provider may keep the earlier version in its recovery history for up to 30 days. In any space, search by meaning and the assistant may have sent its text through us. Duplicates, downloads and exports made before the lock keep what they had, and so may the browsers of people who had it open. In a space kept on this device, the browser may keep the old copy on disk for a while. For something that should never reach us unscrambled, add an empty note, lock it, unlock it, then write in it.
  • People who can edit the space. Without the passphrase they can’t read it or change what’s in it. They can still move it, rename it, copy it or delete it, and put a copy made earlier in its place.
  • Anyone you tell the passphrase. They can open it, copy what’s in it, change it or remove the lock. If someone removes the lock from a card you have open, Atomics tells you: stop typing in it.
  • Anyone who can use your passkey. A card with a passkey opens for whoever can unlock your device or your password manager.
  • What’s on your screen. While it’s open, it’s ordinary text in the page, which browser extensions you allow on Atomics can read.
  • The code we serve. The scrambling is done by code we send to your browser each time you open Atomics. Locking keeps what we store unreadable to us. It can’t protect you from a changed version of that code, whether someone broke in or we were made to change it. If that is the risk you face, keep the file out of any web app.

Unlocking with a passkey

  • Where your browser can, the Lock dialog offers to add a passkey as you lock the card, and Add Passkey… in the right-click menu or ⌘K adds one to a card already locked, once you’ve typed its passphrase. Face ID, Touch ID or your device’s screen lock then opens it, without the passphrase.
  • The passphrase still opens it. A passkey is another way in, not a replacement, so keep the passphrase safe.
  • Asked about the card, your passkey gives your browser a secret that unwraps the card’s key there. That secret never leaves your browser, and we never receive it. The card keeps its key wrapped under that secret, and which passkey to ask, by an ID that isn’t secret.
  • A passkey works only on the site it was made on. One kept in a password manager that syncs may open the card on your other devices too.
  • Your browser uses one passkey for every card it locks, so locking more cards doesn’t fill your password manager.
  • Not every passkey can do this. If yours can’t, Atomics says so and leaves the card as it was. The passkey made for it may stay in your password manager, where you can delete it, and the switch starts off in this browser from then on.
  • Remove Passkeys, on a card you’ve unlocked, takes every passkey off it and leaves the passphrase as it was. It doesn’t change the card’s key, so someone with your passkey who kept a copy of the card from before can still use it to open the card. To shut them out, remove the lock and lock it again.

Changing the passphrase

  • Change Passphrase… in the right-click menu or ⌘K asks for the passphrase the card has now, then a new one. From then on the card asks for the new one, and any passkeys on it keep working. You can change the hint at the same time. Use it for a stronger passphrase or one that’s easier to keep.
  • It doesn’t shut anyone out. The card’s key stays the same and isn’t scrambled again, and everyone who can see the space was sent what the old passphrase unlocks, as are copies of the card. So anyone who knew the old passphrase can still open the card, now and later, and change it. To shut someone out, remove the lock and lock it again with a new passphrase.

If you forget the passphrase

We can’t reset it, and there is no recovery key yet. A forgotten passphrase loses the card for good, so keep it somewhere safe. A card with a passkey still opens with it, for as long as you have the passkey.

Locking or restricting

In a synced space you own, Lock… offers a second way: Restrict who can open it. We check who is asking before we send the content, and people you don’t choose see a locked card and can ask for access. You can always get back in, but the content is stored as it is, so we can read it, and the law could require us to hand it over.

The details

Your passphrase is stretched with PBKDF2-SHA-256 over 600,000 rounds and a random salt into a key that unwraps a random key kept for the card. The card is sealed in 1 MiB pieces with AES-256-GCM, each tied to its place, the lock and the kind of card, so a piece can’t be swapped, cut off or moved to another card without it showing. Changes are checked too. When you lock a card, your browser derives a second key from the card’s key and gives us only a fingerprint of it, and we accept a change to what the card holds or to its lock only with that key. None of this can tell an older copy of the card from the latest, so a copy made earlier, put in its place, opens without a warning. A passkey uses the WebAuthn PRF extension: asked about the lock and a random salt, it gives a 32-byte secret, which HKDF-SHA-256 turns into a key that unwraps the card’s key.

Read the privacy policy