Version 7.0.20 — Live

Your Data Stays Safe On Your Device Only.

KalderaShield is a local-first, open-source credentials manager built with zero-knowledge security architecture, requiring no internet connectivity or third-party cloud infrastructure.

  • No servers.
  • No accounts.
  • Local control.
0 unit tests
0 interface languages
0 platforms
0 telemetry
Platform Support

Get Started

Downloads are served from GitHub Releases; every release is published with its SHA-256 digest and signatures.

Linux

DEB, AppImage, or an inspectable, verifiable CLI script. All distributions.

Download

Android

Android 9.0 and later. Universal or architecture-specific APK.

Download

Browser Extensions

Chrome, Firefox, Edge, Brave and Safari (MV3 / Native Messaging).

Download

CLI

Download and inspect the script first, verify its signature, then run.

Download

Windows

Windows 10 64-bit and later. Setup wizard, MSI or portable build.

Download

macOS

In development — code signing in progress.

Features

Powerful, Resilient, Uncompromising

An architecture designed for frictionless productivity without lowering security boundaries.

OPFS Sandbox

Local-First: SQLite & OPFS Sandbox

Your credentials live in your browser or desktop app's isolated Origin Private File System directly inside a native SQLite database. 100% resilient to network outages.

Native Messaging

Secure Extension Integration

The desktop application communicates with the extension over a dynamically selected loopback TCP port. A pairing token authenticates the connection, and XChaCha20-Poly1305 encrypts message frames.

Air-Gap

Air-Gap Network Policy

The network policy restricts unexpected outbound connections. Offline use is supported; enabled features and configuration can affect network behavior.

Security Architecture

Security architecture

Vault data is encrypted on-device. Protection depends on master-password strength, the KDF parameters stored with the vault, device security, and how the application is used. No cryptographic design guarantees protection in every attack scenario.

AEAD Authenticated

AES-256-GCM

Every record is encrypted using an isolated 256-bit AES-GCM key derived via WebCrypto HKDF-SHA256 per item.

Key Derivation

Argon2id KDF

Argon2id raises the cost of offline password guessing. Defaults: Tauri native desktop/Android, 64 MiB / 4 iterations / 2 lanes; Web/WASM, 32 MiB / 3 iterations / 1 lane. Existing vaults keep their stored parameters.

Zero-Knowledge

Zero Knowledge

The master password and derived keys are processed client-side. Protection also depends on the security of the device running the application and the user's environment.

Browser Integration

Frictionless Autofill in Your Browser

Full Mozilla Public Suffix List (10k+ rules) eTLD+1 domain isolation and closed Shadow DOM autofill protection.

How it works

Four steps from a master password to an encrypted vault

Nothing on this page contacts a server. Every step runs on the device you are reading it on.

  1. You choose a master password

    It never leaves this device in any form, and there is no reset link, because there is no account to reset.

  2. Argon2id derives the key

    The password is stretched into a key with Argon2id, then HKDF-SHA256 splits it into an isolated key for each record.

  3. Every record is sealed with AES-256-GCM

    The vault file on disk holds ciphertext and its authentication tag. Reading one without the key fails rather than returning a wrong value.

  4. You unlock it locally

    Biometrics, a security key or the 24-word recovery kit release the key again on this device. No network request is involved.

Comparison Matrix

Why KalderaShield Stands Apart

Security & Architecture Criteria KalderaShield Cloud Password Managers Legacy Offline Tools
Server requirement None Required None
Account requirement None Required None
Data location On your device On the vendor's server On your device
Works without a network Full No Full
Open source Yes No Varies

This table is an architectural summary based on project documentation and source code published as of September 23, 2026; it is not an independent comparative test. Other products vary by version, plan, and configuration. Third-party features have not been independently verified here.

Transparency & Trust

Security Review & Audit Status

Security documentation and an external audit scope are published. No completed independent third-party report has been published yet.

Take Back Control of Your Passwords

Free, open source, serverless. Download, verify and keep your vault on your device.

Download Installer