Zero-knowledge encryption

Every secret you own.
One vault only you can open.

Passwords, cards, identities, authenticator codes, API keys and encrypted files — protected with end-to-end encryption before they ever leave your device. Not even we can read them.

  • AES-256-GCM, with every key derived on your device
  • Your PIN stays on your device — we never receive it
  • 8 offline recovery keys — no lockout, no backdoor

One vault, everything protected

Every capability of a modern password manager, plus the things developers and teams actually need.

P

Password manager

Logins with usernames, passwords, URLs and custom fields. A strong password generator built in. Notes on everything.

C

Cards & identities

Every card type with number, CVV and expiry. Government IDs and identity documents, stored encrypted with your notes.

A

Built-in authenticator

Scan a QR code once — TOTP codes appear right next to the login they belong to. No separate authenticator app.

K

Developer secrets

API keys, OAuth client IDs and secrets, tokens, SSH keys, certificates — first-class encrypted records, not notes.

F

Encrypted file manager

Folders and files of any type, encrypted on your device before upload. The server only ever stores ciphertext.

O

Organizations & sharing

Share a single item, a folder or a whole collection with your organization — with per-member read, write and delete permissions.

Zero-knowledge, by architecture

Security is not a setting here — it is the only way the system works.

Encrypted before it leaves

Your master password derives your keys on your device (PBKDF2-SHA256, 600,000 rounds). Everything is sealed with AES-256-GCM before upload — the server only ever stores ciphertext it has no way to open.

Your PIN never reaches us

The 6-digit PIN that unlocks a device is stored and checked on that device — we hold nothing derived from it. Even a full copy of our database contains no PIN to attack.

Two steps to sign in, one key to decrypt

Corenexis SSO proves who you are, then a one-time code goes to your email. Neither opens the vault: your master password or device PIN is still required to decrypt anything.

Recovery without a backdoor

Eight one-time recovery keys, downloadable as a file you keep offline. Any one of them resets a forgotten master password. No email resets, no support override — because none is possible.

Cryptographic sharing

Sharing wraps an item's key with the recipient's public key. Permission is enforced by mathematics, not by a flag in a database — someone you have not shared with holds nothing that decrypts.

Search that never leaves the page

Your vault is decrypted in your browser's memory and searched there. We never receive a query, because there is nothing on our side that could answer one.

What we can see. What we never can.

The honest version, without marketing language. Everything in the right-hand column is impossible for us by design — not withheld by policy.

Stored on our servers

What we hold

  • Your email address and display name
  • Your plan, and how much storage you use
  • Encrypted blobs — random-looking bytes
  • How many items you have, and when they changed
  • Sign-in times and IP addresses, for security alerts
Mathematically out of reach

What we can never read

  • Your master password — it never leaves your device
  • Your PIN — it is only ever stored on your device
  • Any password, card number, note or API key
  • File contents, file names, even folder names
  • Your recovery keys, or anything that could rebuild them
  • What you searched for

This is what "zero-knowledge" has to mean to be worth saying. If we were compelled to hand over everything we have, it would still be ciphertext.

What happens when you save a password

Five steps. Only one of them involves us, and by then it is already unreadable.

  1. 1

    You type it in

    The password exists as plain text in one place only: the tab in front of you.

  2. 2

    A key is made for this item alone

    A fresh random 256-bit key is generated for this one entry, then wrapped by your account key — which itself only exists once your master password has been stretched through 600,000 rounds on your device.

  3. 3

    It is sealed

    AES-256-GCM encrypts the entry and stamps it with an authentication tag, so any later tampering with a single byte makes it refuse to open rather than open wrongly.

  4. 4

    Only then does it travel

    What crosses the network is cnx1.<iv>.<ciphertext> — a version tag and two blocks of base64. No field names, no hints, no plaintext.

  5. 5

    We store it without ever opening it

    Our database holds those bytes. We have no key, no copy of a key, and no path that could produce one. When you come back, your device does the decrypting — never our server.

Not just passwords

All of it gets the same encryption. There is no "less sensitive" tier here.

LoginsSites, usernames, passwords, notes
CardsNumbers, expiry, CVV — network detected automatically
IdentitiesPassports, licences, national IDs, addresses
Secure notesAnything that belongs in a locked drawer
AuthenticatorTOTP codes, with QR scan and Google Authenticator import
API keysTokens, connection strings, SSH keys, certificates
FilesEncrypted in chunks — documents, scans, images, backups
OrganizationsShared team vaults with per-member roles

The questions worth asking

Answered plainly, including where the honest answer is uncomfortable.

What if your servers are breached?

An attacker walks away with ciphertext, argon2 password hashes and wrapped keys. None of it decrypts without your master password, which we have never held. That is the entire point of building it this way.

What if I forget my master password?

Use one of your eight recovery keys. If you have lost those too, your data is gone permanently — we cannot restore it. A provider who can reset your password is a provider who can read your vault.

Can your staff read my data?

No, and not as a matter of policy — as a matter of arithmetic. An administrator can suspend an account or see how much storage it uses. There is no view, export or support tool that reveals a single stored value.

Is the 6-digit passcode as safe as the master password?

No, and we would rather say so than imply otherwise. One passcode works on every device you sign in on, so half of what unlocks it is held here — peppered with a key that lives outside the database, so a stolen copy of that database is not enough. An attacker who took our whole server could grind six digits. Your master password and recovery keys never touch us in any form, so if you want that guarantee for unlocking too, simply do not set a passcode.

What if someone steals my phone?

Three wrong passcodes remove it from the account entirely and email you, after which only your master password works. You can sign any device out from anywhere, and the vault re-locks by itself after an hour of inactivity.

What do I have to trust you with?

That the code we serve your browser is the code we describe. Every zero-knowledge web app rests on that, and pretending otherwise would be dishonest. Our strict content policy blocks third-party scripts entirely, so there is one source to trust rather than a dozen.

Simple pricing

Start free. Upgrade when your team or storage grows. Monthly subscription, cancel anytime.

Free

$0/month
  • All vault features, full encryption
  • 500 items
  • 100 MB encrypted storage
  • 10 MB per file
  • 1 organization, 3 members

Pro

$3.49/month
  • Everything in Plus
  • 10,000 items
  • 5 GB encrypted storage
  • 100 MB per file
  • 10 organizations, 20 members each

Max

$6.99/month
  • Everything in Pro
  • Unlimited items
  • 20 GB encrypted storage
  • 100 MB per file
  • Unlimited organizations & members

Your secrets deserve better than a notes app.