Your master password is the root
Argon2id turns it into the vault key. The master password is never stored in browser sessionStorage; after unlock, session state is a zeroized in-memory byte buffer, not a string the page can read.
Security / Overview
KalderaShield is a local-first password manager: your vault lives on your device, encryption happens there, and no account or cloud copy is required. This section explains exactly how that protection works — and where it ends.
There is no KalderaShield account and no server-side vault copy. Your encrypted vault is stored on your device and, if you choose, in encrypted backup files that you move yourself. An attacker cannot breach a server that does not exist.
Every record is encrypted separately. A unique 256-bit AES-256-GCM key is derived per record through HKDF-SHA256, so decrypting one item never exposes another. Titles, usernames, passwords and notes exist in plaintext only inside the authenticated ciphertext payload.
The master password is stretched with Argon2id — 64 MiB of memory, 4 iterations and 2 lanes on desktop and Android — and the parameters are stored in the vault, so an existing vault never silently becomes weaker.
Production builds run behind an air-gap policy: unexpected outbound fetch, WebSocket, WebRTC and similar calls are blocked and logged. The only network traffic is the Have I Been Pwned range check, which sends the first five characters of a SHA-1 hash and never your password.
Argon2id turns it into the vault key. The master password is never stored in browser sessionStorage; after unlock, session state is a zeroized in-memory byte buffer, not a string the page can read.
Windows Hello (TPM 2.0), macOS Touch ID (Secure Enclave), Android BiometricPrompt (AndroidKeyStore) and PRF-capable FIDO2 keys wrap the unlock payload. The vault file itself is never hardware-sealed, so a lost device never locks you out.
The published threat model states which attacks are defended, which are only partially defended, and which are out of scope — including malware running in your own OS session. Product claims are not allowed to promise more.
No local application can protect a vault on a compromised device: malware running with your OS account while the vault is unlocked, keyloggers, privileged screen capture and memory inspection are all outside this model. Hardware unlock is a convenience wrapper, not a replacement for the master password. An independent third-party audit has not been completed yet — that is stated openly, not hidden.
64 MiB, 4 iterations, 2 lanes for new desktop and Android vaults; 32 MiB, 3 iterations, 1 lane for web builds.
HKDF-SHA256 derives a unique key per record and per attachment, with the record id as salt. Tampered ciphertext fails authentication.
Unexpected outbound fetch, XHR, WebSocket, sendBeacon, EventSource and WebRTC destinations are blocked and recorded as security events.
No. There is no account and no server-side vault. Optional sync providers such as WebDAV and S3 upload only the encrypted payload to storage that you configure and own.
No, and no one else can either. Unlock with the master password, unlock with the 24-word BIP-39 recovery key, or restore an encrypted backup. Without one of those, the vault cannot be opened.
Not yet. The audit status page states this openly and describes the automated verification that is in place today. Hiding an unfinished audit would contradict everything else on this site.