Yourpasswords.Yourvault.Zeroknowledge.
Every credential is encrypted on your device before it ever leaves your browser. Not us, not Google, not anyone can read your vault — only your master password can open it.
Zero-knowledge
We can't access your data
Client-side encryption
Before it leaves your device
No credit card. No tracking. Open source.
Built on the same model trusted by leading password managers — envelope encryption with Argon2id key derivation.
Strong by default
AES-256-GCM encryption protects your data.
Modern security
Argon2id key derivation resists brute-force attacks.
Privacy first
Zero-knowledge architecture — we never see your data.
Verify to trust
Open source and auditable. Re-verify every update.
Trusted by privacy-conscious users
Vault
6 credentials
GitHub
github.com
Gmail
mail.google.com
AWS Console
aws.amazon.com
Netflix
netflix.com
Stripe
stripe.com
Discord
discord.com
Features
Everything a vault should do. Nothing it shouldn't see.
Client-side encryption pipeline
Your master password never leaves the browser. It derives keys locally; only ciphertext ever crosses the network.
Locks itself
Auto-locks after 5 idle minutes, 60 seconds in a hidden tab, and wipes keys from memory instantly.
Key rotation
Change your master password and every credential is re-encrypted with a brand-new key — locally.
Search & tags
Organize credentials with tags and find anything instantly — without decrypting a single secret.
Your data, portable
One-click export decrypts your vault locally into JSON. No lock-in, no gatekeeping, ever.
How it works
Three steps to a sealed vault.
Sign in with Google
Your Google account identifies you — it never sees or holds your secrets.
Set a master password
Argon2id turns it into encryption keys on your device. We store only a verifier — never the password.
Store everything
Each credential is sealed with AES-256-GCM before upload. Reveal requires re-confirming it's you.
Seal your passwords in black.
Free, open source, zero-knowledge. Your first credential is 30 seconds away.