Store credentials, payment cards, and sensitive files with military-grade client-side encryption. Your keys never touch a server, and even our database cannot read your vault.
VaultPlus is a local-first password app — your passwords live on your own device first, and only go to the cloud if and when you say so.
When you save a password, it's stored right there on your own phone or computer — like a locked drawer in your own home, not a locker in someone else's building.
The instant you hit save, VaultPlus locks it up using the same kind of encryption banks rely on. To anyone else, it just looks like meaningless static.
The key that unlocks your vault is your master password. It never leaves your device and we never store a copy — so nobody, including us, can peek inside.
Connect your own Google Drive anytime for an extra safety net. VaultPlus stores a locked copy there, still unreadable to anyone but you, and only if you turn it on.
Try our WebCrypto-powered random generation directly in your browser. Pure cryptographically secure entropy.
You don't need to understand any of this to be safe — but if you want the engineering-level detail behind "only you can read your vault," here it is. Your master password is never transmitted across the network; all encryption happens on your own device.
Your master password is fed into PBKDF2 with a unique 128-bit salt and 200,000 SHA-256 iterations to derive a 256-bit cryptographic encryption key.
In plain English: your password is stretched and reshuffled 200,000 times so guessing it by brute force would take far longer than a lifetime.
All passwords, cards, and notes are encrypted using Galois/Counter Mode (GCM). An accompanying 128-bit auth tag guarantees tamper resistance.
In plain English: your data is scrambled into unreadable text, and it also seals itself so any tampering is instantly detected.
Only the encrypted ciphertext is written to IndexedDB and synchronized with your personal Google Drive. Even with a full database breach, nobody can read your secrets.
In plain English: what leaves your device is already locked. Even if a server or Google Drive were broken into, all an attacker gets is scrambled noise.
Every tool you need to replace insecure spreadsheets and browser autofills with an enterprise-level personal vault.
Queries the HaveIBeenPwned database of over 10 billion leaked credentials using SHA-1 k-Anonymity. Only the first 5 characters of your hash prefix are sent—your actual password never leaves your browser.
Unlock in under a second using Touch ID, Face ID, Windows Hello, or a quick PIN code for seamless daily access.
Share credentials securely with family or teammates using asymmetric key encryption with automatic expiration and view-only permissions.
Keep up to 7 automated revision snapshots stored exclusively in your own private Google Drive with 1-click restore.
Seamlessly import your passwords from Google Chrome, Bitwarden, 1Password, or LastPass in seconds.
Most password managers store your encrypted vault on their proprietary cloud servers. VaultPlus gives you complete ownership.
Everything you need to know about VaultPlus security and cryptography.