Encrypted locally
Sensitive credential data is encrypted before it is stored, using Argon2id and XChaCha20-Poly1305.
Private by design
PassVault keeps passwords, secure notes, and two-factor authentication details in a local encrypted vault—without accounts, advertising, analytics, or cloud sync.
A vault, not a service
Your vault is stored on your device. PassVault has no application server that receives your passwords, recovery key, activity, or TOTP setup data.
Sensitive credential data is encrypted before it is stored, using Argon2id and XChaCha20-Poly1305.
Use your master password or an optional device biometric. PassVault never receives your Face ID, Touch ID, or fingerprint template.
Create an encrypted .pvault backup with a separate password and save it to a location you choose.
Everyday essentials
Store logins and secure records, search locally, mark favorites, and move items between folders.
Add compatible two-factor setup keys to a login and generate time-based codes entirely on the device.
Review weak, reused, or old passwords locally so you can decide what to improve.
Know the boundary
Because PassVault has no remote copy of your vault, the publisher cannot recover a forgotten master password. Keep a tested encrypted backup and its password in safe, separate places.