A cross-platform vault that encrypts everything on your device before it syncs. Biometric unlock, AES-256-GCM, auto-lock — and a server that only ever sees ciphertext.
A cross-platform vault that encrypts everything on your device before it syncs. Biometric unlock, AES-256-GCM, auto-lock — and a server that only ever sees ciphertext.
Zero-knowledge by designEverything is encrypted on your device before it ever syncs. The server stores ciphertext and nothing else — we cannot read your vault, and neither can anyone who breaches us.
AES-256-GCM + PBKDF2Secrets are sealed with AES-256-GCM; your master key is derived with PBKDF2 and never leaves the device. Keys live in the secure enclave, not in app storage.
Biometric unlockFace ID and fingerprint open the vault in a tap, backed by secure-enclave key storage. No password typing on a phone keyboard.
Encrypted cloud syncKeep the same vault on phone, tablet, and desktop. Sync moves encrypted blobs only — plaintext never crosses the wire.
Auto-lock & screenshot blockThe vault re-locks on a timeout you choose (1 minute to 1 hour), and secure screens refuse to appear in screenshots or the app switcher.
Strong password generatorGenerate long, high-entropy passwords with the character rules a site actually accepts — then save them straight into the vault.
Zero-knowledge by designEverything is encrypted on your device before it ever syncs. The server stores ciphertext and nothing else — we cannot read your vault, and neither can anyone who breaches us.
AES-256-GCM + PBKDF2Secrets are sealed with AES-256-GCM; your master key is derived with PBKDF2 and never leaves the device. Keys live in the secure enclave, not in app storage.
Biometric unlockFace ID and fingerprint open the vault in a tap, backed by secure-enclave key storage. No password typing on a phone keyboard.
Encrypted cloud syncKeep the same vault on phone, tablet, and desktop. Sync moves encrypted blobs only — plaintext never crosses the wire.
Auto-lock & screenshot blockThe vault re-locks on a timeout you choose (1 minute to 1 hour), and secure screens refuse to appear in screenshots or the app switcher.
Strong password generatorGenerate long, high-entropy passwords with the character rules a site actually accepts — then save them straight into the vault.
Zero-knowledge by designEverything is encrypted on your device before it ever syncs. The server stores ciphertext and nothing else — we cannot read your vault, and neither can anyone who breaches us.
AES-256-GCM + PBKDF2Secrets are sealed with AES-256-GCM; your master key is derived with PBKDF2 and never leaves the device. Keys live in the secure enclave, not in app storage.
Biometric unlockFace ID and fingerprint open the vault in a tap, backed by secure-enclave key storage. No password typing on a phone keyboard.
Encrypted cloud syncKeep the same vault on phone, tablet, and desktop. Sync moves encrypted blobs only — plaintext never crosses the wire.
Auto-lock & screenshot blockThe vault re-locks on a timeout you choose (1 minute to 1 hour), and secure screens refuse to appear in screenshots or the app switcher.
Strong password generatorGenerate long, high-entropy passwords with the character rules a site actually accepts — then save them straight into the vault.
ZERO-KNOWLEDGE, CONCRETELYWhat the server actually storesYour master password never leaves the device, and neither does the key derived from it. Encryption happens before sync, so a breach of our infrastructure yields opaque blobs.The trade-off is honest: lose your master password and we genuinely cannot recover your vault. That is the point.
ZERO-KNOWLEDGE, CONCRETELYWhat the server actually storesYour master password never leaves the device, and neither does the key derived from it. Encryption happens before sync, so a breach of our infrastructure yields opaque blobs.The trade-off is honest: lose your master password and we genuinely cannot recover your vault. That is the point.