Client-Side AES-256-GCM · PBKDF2 200,000 Iterations

The zero-knowledge vault for secrets you can't afford to lose.

Store credentials, payment cards, and sensitive files with military-grade client-side encryption. Your keys never touch a server, and even our database cannot read your vault.

Zero-Knowledge Architecture
WebCrypto Native Engine
Local-First IndexedDB
Google Drive Private Sync
VAULT UNLOCKED
⌘K
GitHub Enterprise
octocat@github.com
Chase Sapphire Reserve
•••• •••• •••• 4821
AWS Cloud Console
ops-admin@company.internal
Office Wi-Fi 6 (5GHz)
SSID: VaultHQ_Enterprise
Interactive preview · Click eye or copy icon
Open Full Dashboard
How It Works

No jargon. Here's exactly what happens to your data.

VaultPlus is a local-first password app — your passwords live on your own device first, and only go to the cloud if and when you say so.

Your Device
You type a password
Encrypted
Locked Vault On Your Device
Saved locally, works offline
Only if connected
Your Google Drive
Optional encrypted backup
VaultPlus servers never see any of this — your data never passes through them
STEP 1

Your vault lives on your device

When you save a password, it's stored right there on your own phone or computer — like a locked drawer in your own home, not a locker in someone else's building.

STEP 2

It's scrambled before it's saved

The instant you hit save, VaultPlus locks it up using the same kind of encryption banks rely on. To anyone else, it just looks like meaningless static.

STEP 3

Only you hold the key

The key that unlocks your vault is your master password. It never leaves your device and we never store a copy — so nobody, including us, can peek inside.

STEP 4

Google Drive backup — only if you want it

Connect your own Google Drive anytime for an extra safety net. VaultPlus stores a locked copy there, still unreadable to anyone but you, and only if you turn it on.

We literally can't see your passwords
Works perfectly with no internet connection
Cloud backup lives in your Google Drive, never ours
Live Engine Demonstration

Generate unbreakable passwords instantly.

Try our WebCrypto-powered random generation directly in your browser. Pure cryptographically secure entropy.

k9#mP$91!vQx7Wz4@Lp2
Entropy Strength:124 bits · Military Grade
Password Length20 chars
The Technical Details

For the curious: exactly how the encryption works.

You don't need to understand any of this to be safe — but if you want the engineering-level detail behind "only you can read your vault," here it is. Your master password is never transmitted across the network; all encryption happens on your own device.

01

Key Derivation (PBKDF2)

Your master password is fed into PBKDF2 with a unique 128-bit salt and 200,000 SHA-256 iterations to derive a 256-bit cryptographic encryption key.

In plain English: your password is stretched and reshuffled 200,000 times so guessing it by brute force would take far longer than a lifetime.

Salt: 128-bit CSPRNG
Rounds: 200,000 iterations
Key: AES-256 Symmetric
02

Authenticated AES-256-GCM

All passwords, cards, and notes are encrypted using Galois/Counter Mode (GCM). An accompanying 128-bit auth tag guarantees tamper resistance.

In plain English: your data is scrambled into unreadable text, and it also seals itself so any tampering is instantly detected.

Cipher: AES-GCM-256
IV: 96-bit unique nonce
Tamper Tag: 128-bit GCM MAC
03

Zero-Knowledge Storage

Only the encrypted ciphertext is written to IndexedDB and synchronized with your personal Google Drive. Even with a full database breach, nobody can read your secrets.

In plain English: what leaves your device is already locked. Even if a server or Google Drive were broken into, all an attacker gets is scrambled noise.

Server Exposure: None (Zero)
Cloud Storage: User's Own Drive
Master Key: Stays in device RAM
Full Capability Suite

Engineered for absolute privacy & speed.

Every tool you need to replace insecure spreadsheets and browser autofills with an enterprise-level personal vault.

Dark Web & Breach Sentinel

k-Anonymity Verified

Queries the HaveIBeenPwned database of over 10 billion leaked credentials using SHA-1 k-Anonymity. Only the first 5 characters of your hash prefix are sent—your actual password never leaves your browser.

Vault Vulnerability Scan: Clean
0 exposed passwords detected in public breach dumps
Health: 100/100

Biometrics & 4-Digit PIN

Unlock in under a second using Touch ID, Face ID, Windows Hello, or a quick PIN code for seamless daily access.

Desktop & Mobile FIDO2Enabled

End-to-End Secret Sharing

Share credentials securely with family or teammates using asymmetric key encryption with automatic expiration and view-only permissions.

Family & Team P2P1 to 30 Days

Google Drive 7-Version Backup

Keep up to 7 automated revision snapshots stored exclusively in your own private Google Drive with 1-click restore.

Rolling Snapshot History7 Revisions

1-Click CSV Migration

Seamlessly import your passwords from Google Chrome, Bitwarden, 1Password, or LastPass in seconds.

Supported FormatsChrome · Bitwarden · 1P
Technical Transparency

Why VaultPlus is fundamentally different.

Most password managers store your encrypted vault on their proprietary cloud servers. VaultPlus gives you complete ownership.

Security DimensionVaultPlusTraditional Cloud ManagersBrowser Autofill
Zero-Knowledge ArchitectureOnly you can ever unlock your data Yes (100% Client-Side)Partial / Server DependentNo
Key Derivation StandardsHow hard it is to crack your master passwordPBKDF2 200k rounds100k - 600k roundsSystem Keychain Only
Cloud Storage CustodyWho actually holds your backup Your Own Google DriveVendor's Central CloudBrowser Vendor Cloud
Offline-First PWAWorks with no internet connection Yes (Local IndexedDB)Requires Desktop ClientYes
Asymmetric P2P SharingSecurely share a password with family/team Included FreePaid Enterprise TierNo
Cost100% Free$3 - $7 / monthFree (Tied to ecosystem)
←Scroll horizontally to compare all features→

Frequently Asked Questions

Everything you need to know about VaultPlus security and cryptography.

Take control of your digital identity.

No credit card, no telemetry, no tracking. Set up your client-side encrypted vault in under 60 seconds.