Every record is read locally
The vault is decrypted in memory on your device and each item is scored. Nothing about the audit is transmitted.
Product / Security audit
The audit scores your vault and separates each problem: short passwords, passwords shared between accounts, passwords in known breach data, accounts with no second factor, plain HTTP links and records nobody has touched in a year.
Most password audits tell you a score and stop. This one splits the score into the individual problems that caused it, because "your vault is weak" is not actionable while "this one account has no second factor" is.
Weak, reused and breached are tracked separately. The breach check runs against the k-anonymity style range queries used by Have I Been Pwned, so it can compare your passwords against a known corpus without sending the passwords themselves anywhere.
The same categories are available as built-in smart folders, so you can jump straight from a finding to the item that caused it instead of hunting through the list.
The vault is decrypted in memory on your device and each item is scored. Nothing about the audit is transmitted.
Weak, reused, breached, missing second factor, insecure transport and outdated are counted independently rather than folded into one number.
Each finding links to the record that produced it, so a fix is one click away rather than a manual search.
The built-in generator produces a replacement with the character classes you choose, so a weak password can be replaced without leaving the audit flow.
The audit measures your vault against known heuristics and known breach corpora. It cannot tell you whether a password you still use was exposed somewhere that has never published a dataset, whether a strong password is reused somewhere it could not check, or whether an account you saved is still yours to access. It reports what it can see in your own data, and nothing more.
Passwords are compared using range queries so only a hash prefix leaves the device, and the passwords themselves never do.
Scoring happens against your decrypted vault on the device, so the audit works with no connection at all.
Weak, reused, breached, missing 2FA, insecure HTTP and outdated records are counted independently.
No. The scoring runs locally. The breach comparison uses range queries, so only a hash prefix is involved and the password itself never leaves the device.
Whenever you add or change records, and after adding a large import from another manager. A large import is the most common reason a strong vault suddenly scores badly.
No. The score describes the passwords in your vault, not whether any of them have been exposed. It measures what is recoverable from your own data.