Vault3 encrypts every password, note and card on your device, before anything is sent. The server stores only the encrypted result. The key that opens it is built in your browser and stays there.
what you type, on your device
what the server receives and stores
How it works
Your Master Password is the one you choose and keep in your head. Your Secret Phrase is twelve ordinary words your browser generates at sign-up and writes into your Emergency Kit. Both stay on your device.
Unlocking combines your two secrets into a single key. The derivation is deliberately slow, which is what puts large-scale password guessing out of reach. The server receives a separate key that only proves your identity.
Every item is encrypted under its own key before it leaves your device. A full copy of the database contains only the encrypted text shown above.
Features
Logins, notes, cards and identities. The server stores a count of your items and nothing about what they are — titles included.
Your second secret is twelve everyday words, picked at random by your browser. Easy to write down, possible to remember, and far too many combinations for anyone to search through — a quantum computer included.
Save a login on your laptop and it appears on your phone the same second, encrypted the whole way across. Changes are pushed as they happen rather than fetched on a schedule.
Random characters, or words that are easy to read aloud. The strength meter reports the actual work an attacker would need, and rates a weak password as weak.
Add a six-digit code from your authenticator app at sign-in. Every device you are signed in on is listed, and you can sign any of them out from any other.
A new device signing in, a changed Master Password, two-factor switched off: each one reaches you as it happens, in the app and by email.
Plain answers
One cookie. No trackers.
Vault3 uses one cookie, and only to keep you signed in. There is nothing to agree to and nothing to switch off — no analytics, no advertising, nobody else watching.