How Legatus is built
Legatus is a Next.js application on Vercel with Supabase behind it, encrypting vault contents in the browser with the Web Crypto API. It ships no third-party trackers and no third-party scripts; the only measurement is a first-party visit beacon on the public pages, which you can switch off. This page records the stack, the type, and the decisions worth explaining.
The stack
Legatus runs on Next.js 16 with the App Router, deployed to Vercel, with Supabase providing Postgres, authentication, file storage and scheduled jobs. Transactional email goes through Resend. There is no state management library and no component framework — the interface is plain React and CSS custom properties.
| Layer | Choice | Why |
|---|---|---|
| Framework | Next.js 16, App Router | Server rendering, so pages exist for readers who do not execute JavaScript |
| Hosting | Vercel | Edge delivery; TTFB around 11ms from Mumbai |
| Data | Supabase / Postgres | Row Level Security enforced at the database, not in application code |
| Crypto | Web Crypto API | Browser-native. No third-party cryptography library in the trust path |
| Resend | Transactional only. No marketing list exists | |
| Analytics | First-party only | A visit beacon that alerts a private chat and stores nothing. See below |
What is deliberately absent
Legatus loads no third-party analytics, no advertising pixels, no tag manager, no session replay and no third-party scripts of any kind. The Content-Security-Policy permits scripts only from this origin, and typefaces are self-hosted, so opening a page contacts no server other than this one.
What it does run is a first-party visit beacon on the public pages — the ones you are reading now. It sends an alert to a private chat when someone visits, recording the IP address, approximate city, browser and which pages were read. It writes nothing to a database, sets no cookie, and carries no identifier that would recognise you on another website. It does not run inside the vault, on the nominee or administrator areas, or on the sign-in and account-creation pages.
For a product whose proposition is that it cannot read your data, shipping a third-party tracker that reads your behaviour would be an odd contradiction — which is why the one piece of measurement here is first-party, disclosed in full on the privacy policy, and switchable off from that page in a single click. What is still missing, deliberately, is any aggregate view: there is no funnel data, no heatmaps and no dashboard, because nothing is stored to build one from.
Typography
Headings and reading prose are set in Cormorant Garamond, a book face. Labels, data and captions are JetBrains Mono. Both are self-hosted through next/font, so no request reaches Google Fonts.
An earlier build loaded them by CSS @import from Google Fonts, which the production Content-Security-Policy silently blocked — the site rendered in system serif and monospace for a while without any console error to say so. Self-hosting fixed the blocking and removed the third-party request at the same time.
Cryptographic parameters
AES-256-GCM for vault contents. PBKDF2 at 310,000 iterations to derive the key from a master passphrase, following the OWASP recommendation for SHA-256. RSA-2048 with OAEP for wrapping the vault key to each nominee. All of it in the browser.
None of this has been independently audited, which is stated here and on the limitations page rather than left for a reader to discover.
Credits
Legatus was designed and built by Suman Debnath, operating as House of Namus. It is a pre-launch product offered free of charge, built and maintained by one person rather than a team.