Zero-knowledge, end-to-end encrypted

The credential manager for everything, not just passwords.

Passwords, TOTP codes, SSH and PGP keys, API credentials, crypto wallets, database logins, and more — encrypted on your device before it ever reaches our servers. We can't read your vault. Neither can anyone who breaches us.

How it works

From master password to protected, everywhere

01

Create your vault

Your master password never leaves your device. It's run through Argon2id locally to derive the key that protects everything — we never see it, and we never store it.

02

Save anything

Logins, TOTP codes, SSH and PGP keys, API credentials, crypto wallets, database logins, WiFi passwords, secure notes — one vault for every kind of secret you actually have.

03

Access it everywhere

Web, Windows, Android, and a Chrome extension all sync through one account — every device decrypts locally with your key, never through us.

04

Stay in control

See every device that's ever signed in, revoke any of them instantly, and get notified if a login shows up from a location that doesn't look like you.

Features

Everything a password manager should have done from the start

Every kind of credential

Logins, TOTP, recovery codes, crypto wallets, SSH keys, PGP keys, API credentials, payment cards, identity documents, secure notes, WiFi, database logins, software licenses, and env-variable bundles.

Live TOTP codes

Every TOTP item shows a live, auto-refreshing 6-digit code with a countdown and one-tap copy — paste it straight into a login form.

Built-in generator tools

Password and passphrase generation, SSH (Ed25519) and PGP keypair generation, BIP-39 wallet mnemonics, hash/HMAC digests, and a k-anonymous breach check — all computed locally.

Every platform, one account

Web, Windows, Android, and a Chrome extension, all syncing the same encrypted vault in real time.

Recovery Key, not a backdoor

A one-time Recovery Key lets you reset a forgotten master password without losing your vault — and without us ever being able to do it for you.

Device-aware security

Every login is tied to a recognized device; a login from an unfamiliar location surfaces an in-app alert, and any device can be revoked instantly.

Security guarantee

We built this so we couldn't read your vault even if we wanted to

  • Your master password is never sent to our servers — Argon2id and HKDF run entirely on your device.
  • Every vault item is encrypted with AES-256-GCM before it leaves your device. We store ciphertext, nothing else.
  • Even a full breach of our database exposes only opaque, encrypted blobs — not your passwords, keys, or notes.
  • A strict Content Security Policy and HttpOnly, tamper-resistant session cookies limit what a scripting attack could ever reach.
  • New logins from an unrecognized location trigger an in-app alert, and every device can be viewed and revoked at any time.

The honest trade-off

Real zero-knowledge encryption means real consequences: if you lose both your master password and your Recovery Key, your data is permanently, unrecoverably gone. There is no support-side reset — because there's no way for us to build one without also building a way to read your vault. We'd rather tell you that plainly than pretend otherwise.