Product / Password vault

One vault for every kind of credential

Five record types, folders, tags, smart folders and full-text search — all encrypted on your device, all readable offline.

What it does

A vault that does not need a server

The vault stores five kinds of record: logins, payment cards, identities, secure keys and secure notes. Every record is encrypted with its own key, so one record being broken never reveals another.

Organisation is local too. Folders, tags, favourites and built-in smart folders such as "has 2FA" or "missing 2FA" are computed on the device from your own data, not from a server-side index.

Search runs locally across titles, usernames and URLs, with diacritic-insensitive matching, so it keeps working with no connection at all.

How it is stored

You choose the master password

Argon2id stretches it into a key. The parameters are recorded in the vault, so an existing vault never silently gets weaker or stronger.

Each record gets its own key

A unique 256-bit AES-256-GCM key is derived per record through WebCrypto HKDF-SHA256, using the record id as the salt.

The database holds ciphertext

Titles, usernames, passwords and notes are masked in the SQLite columns; the real values exist only inside the encrypted payload.

Five record types, one form

Logins, cards, secure keys, identities and notes share one editor, and a payment card keeps its number, expiry, CVV and ATM PIN in separate masked fields.

Security Architecture

What the encryption does and does not promise

Read this before you trust it with your vault

Every record is encrypted on your device with a key that never leaves it. Protection still depends on your master password strength, the KDF parameters stored in your vault, the security of the device itself, and how you use the application. No cryptographic design promises absolute protection against every attack, and a compromised device can read a vault that has already been unlocked.

Argon2id

Key derivation

New desktop and Android vaults use 64 MiB of memory, 4 iterations and 2 lanes. Web builds use 32 MiB, 3 iterations and 1 lane.

AES-256-GCM

Per-item isolation

Breaking one record does not reveal any other record in the vault, because no two records share a key.

SQLite

Masked columns

Sensitive columns hold a static placeholder token. The plaintext exists only inside the AES-256-GCM payload.

Frequently Asked Questions

About the vault

What happens if I forget my master password?

You can unlock with the 24-word BIP-39 recovery key and reset the password, or restore an encrypted backup. Without either, the vault cannot be opened, because nothing on your device can re-derive the key.

Can I open the same vault on another computer?

Yes. Export an encrypted backup and restore it on the other device with your master password. The vault file is portable and not tied to one machine.

Does search send anything to a server?

No. Search runs against the local database on your device, including diacritic-insensitive matching.

Related pages

Download Installer