Choose a master password you can remember
Argon2id stretches it into the vault key, but no parameter change can recover a password you did not store. The 24-word recovery key is the second path — save it outside the app.
Support / FAQ
Short answers, no marketing layer. Every answer that makes a claim links to the page that backs it.
KalderaShield is a free, open-source password manager under the Apache-2.0 license. There is no paid tier, no subscription and no premium version — the roadmap deliberately contains none, and a pricing page would be misleading for a product with no price.
It is local-first: your vault is stored encrypted on your device, there is no KalderaShield account and no server-side copy of your data. Optional sync through your own WebDAV or S3 storage uploads only the encrypted payload.
It runs on Windows, Linux and macOS desktops, on Android, and as a browser extension for Chromium and Firefox that fills credentials from the paired desktop app.
Argon2id stretches it into the vault key, but no parameter change can recover a password you did not store. The 24-word recovery key is the second path — save it outside the app.
The .ks backup is encrypted with your backup password and restorable on any platform. Keep one copy outside the device.
Compare the installer's SHA-256 hash with the published checksums. One command, and you know you are running the pipeline's output.
No cloud sync between KalderaShield servers. No account system, no email-based password reset. No recovery of a lost master password — nobody, including us, can re-derive it. No protection against malware running in your own OS session while the vault is unlocked. No pricing page, because there is nothing to buy. Each of these is a design decision documented in the threat model or the plan, not a missing feature.
CSV and JSON import normalizes data from common managers before saving; the fuzz gate hammers the importer with malformed files on every release run.
The .ks format uses Argon2id and AES-256-GCM. Backups restore on Windows, Linux, macOS and Android alike.
The air-gap policy blocks unexpected outbound traffic; the extension declares data collection of none. There is nothing to opt out of.
Yes, under the Apache-2.0 license. No subscription, no premium tier, no feature locked behind payment.
No. There is no account and no server-side vault. You create a local vault protected by a master password, optionally wrapped by your device's biometrics.
Unlock with the 24-word BIP-39 recovery key, or restore an encrypted backup. Without one of those, the data cannot be recovered — by you, by the app, or by anyone else.
Yes, through CSV and JSON export files. The importer normalizes the common formats before saving, and malformed input is handled by a fuzz-tested parser rather than trusted.
Export an encrypted .ks backup, transfer the file yourself, and restore it with the master password on any platform. The vault is portable by design.
Not automatically. There is no KalderaShield cloud. Optional sync uploads only the encrypted payload to WebDAV or S3 storage that you configure and own.
The extension stores no vault — it holds nothing when the desktop app is absent. Fills are bound to validated tab URLs at eTLD+1, bridge frames are encrypted, and broad credential queries return sanitized metadata. The residual risks are documented in the threat model.
No independent audit has been completed yet — the audit status page states this openly along with the automated verification that exists. Claiming otherwise would be easy; auditing is how it gets fixed.