Sharp#Soft
concept  ·   ·  5 min read

No Master Account: Why Someone Should Have to Knock

Every service swears it respects your privacy. The question that actually matters is simpler: who has a spare key?

Somewhere in most online services there is a person who can open your account. Not a hacker — an employee. A support agent who can read your messages to "help with your ticket." An administrator who can be added to your shared folder. A backend operator who, given the right request, can hand over your files. Usually they are decent people following rules. But the ability is built into the building, and an ability that exists can be used — by a curious insider, by an attacker who steals an admin's credentials, by a court order, by whoever owns the company next year.

We have quietly accepted this as the price of using anything online. It is not. It is a design choice — and a different choice is possible.

A sealed lock with no spare key — a door no operator can open

The room with a spare key

Think of your data as a room. In the ordinary arrangement, you have a key — but so does the landlord. The lock works perfectly against strangers; it does nothing against the person who built the building and kept a copy. The help desk has that copy. The admin console has that copy. The backup system has that copy. Each is a reasonable convenience, and each is a spare key to your room.

The trouble with a spare key is that it does not care about intentions. It protects you exactly as much as everyone who holds it behaves — forever, under every pressure. The promise "we won't look" is only ever as strong as the people making it and the absence of anyone able to compel them. The moment the architecture can open your room, your privacy rests on conduct, not on the lock.

(There is also a legal case for why this matters — why privacy is a right, not a privilege the operator grants. That is its own argument. This is the architectural one: even when the law is on your side, the spare key is still sitting in the drawer.)

A door where even the builder has to knock

Now imagine a building where the lock was made differently — where the only key was cut on your own device, by you, and no master copy was ever filed. The builder can construct the room, store it, move it between your devices, and still not be able to open it. Not because they promised, but because they never held the key.

That is the choice Sharp#Soft makes. The keys that protect your content are generated on your own device and never leave it; what the system stores for you is sealed, opaque even to the people who run it. There is no master account that can be quietly added to a shared space. There is no help-desk button that reveals the contents of a sealed file. When you share something, you cryptographically invite the specific people you mean to — and removing someone means the next version of the lock simply stops opening for them.

Your data sealed behind a key only you hold

The consequence is small to state and large in practice: someone should have to knock. Access becomes a thing you grant, person by person, with the key in your hands — not a thing a server quietly arranges on your behalf. The operator becomes, by design, just another party standing on the outside of your door. Even the builder has to knock.

This is not a setting you switch on. It is the shape of the system. A help desk cannot read what it has no key to; an insider cannot misuse an override that does not exist; a court order can only compel what the operator actually holds — and what the operator holds is sealed.

Being honest about the seams

A claim worth trusting names its own limits. Sealing your content does not make you invisible. To deliver anything at all, the system still has to know that some account exists and that some relationship connects two people — and that operational shape is not encrypted away. We keep it to a minimum, and we say so plainly rather than pretend it is gone. What is protected is the part that matters most: the contents of your room, and the decision of who gets in.

Nor does any lock survive you handing over your own key. If you are compelled to unlock your device, cryptography cannot rescue you — and no honest system claims otherwise.

What this means for you

Day to day: nothing — and that is the point. You do not configure this, audit it, or remember to switch it on. You use the product, and the property holds underneath: your data sits behind a door only you hold the key to, and everyone else, the operator included, has to be let in.

So the next time a service assures you your privacy is safe in their hands, it is worth asking the quieter question: do they keep a spare key to my room? For almost everything online, the answer is yes. It does not have to be. A door where even the builder has to knock is not a luxury — it is simply a better lock, and the technology to fit one already exists.