01 / Your digital life

Your accounts,
on your device.

Keep your passwords, passkeys and private notes in an encrypted vault on your own device. The core features work offline, and you don’t need a cloud account.

Your accounts and codes in one vault.Illustration with made-up data
Works offlineEncrypted local storageOptional device sync

Inside Vault

Your accounts and codes,
right where you need them.

Sign in with Smart Login, tie your vault to a USB drive, and keep codes and strong passwords handy. Encrypted device pairing brings it to your phone.

Smart Login

From your vault straight into your account.

Pick an account and start Smart Login. Vault finds a supported sign-in form, checks the website and puts your saved username and password in the right fields. The walkthrough shows a GitHub example with a saved authenticator code.

CAPTCHAs, security-key prompts and extra approvals are up to you. Support for websites, browsers and operating systems depends on your setup.

The walkthroughs use made-up data. What works varies between websites, browsers and operating systems.

Tools inside Vault

Tools for every day
and for the bad ones.

Move your accounts into Vault, keep them up to date, and have a plan for getting back in if you lose access.

01Passkeys & Smart Login

Use your saved sign-ins.

Start Smart Login from a saved entry. Vault opens the website, checks that it’s the right one and finds the sign-in fields before filling in your details. It can handle supported multi-step forms, and if it spots a compatible two-factor prompt, it can enter your saved authenticator code. Passkeys are a separate sign-in method that you confirm yourself.

02Security dashboard

Find passwords worth changing.

The local dashboard points out weak and reused passwords. Turn on Have I Been Pwned checks and Vault looks for known breaches using only a hash prefix. Your password itself isn’t sent.

03History & trash

Go back to an earlier password.

See a password’s history and restore an older one. Deleted entries stay in the trash until you remove them for good.

04Import, backup & recovery

Plan for losing access.

Import your existing logins and export encrypted backups. Set up an emergency kit or split recovery shares, and keep them somewhere other than the vault.

05Optional synchronization

Your vault on both devices.

Move your vault from your computer to your phone over the same Wi-Fi. Scan a temporary QR code and the vault is sent encrypted, then saved locally on the phone. Once they’re paired, P2P sync keeps your entries up to date without a cloud account.

06Developer tools

Use Vault from your terminal.

Use the vault from the CLI or the terminal interface. There’s also secret injection, Git credential integration and an SSH agent. The documentation explains how to set them up.

How Vault protects your data

Several layers
of protection.

Vault encrypts the local file and uses separate keys for separate jobs. Auto-lock, an optional key file and clipboard clearing help while you’re using it.

01 / Argon2id

Guessing gets slow and expensive.

Argon2id turns your master password into a key using a memory-heavy calculation. That makes guessing passwords against a stolen vault file more expensive.

02 / HKDF-SHA512

One key per job.

HKDF-SHA512 derives separate keys for the vault, its entries, integrity checks and search. Every entry also gets its own encryption key.

03 / XChaCha20-Poly1305

Encrypted and authenticated.

XChaCha20-Poly1305 encrypts the vault and its entries. Its authentication checks reject encrypted data that’s been modified.

Lock when you step away.

Set a timeout and the vault locks when you’re inactive. On supported platforms, Vault also watches for workstation locking and whether a removable vault is still there.

Add your own key file.

Use an optional key file together with your master password. Back it up separately. If you lose a required key file, you may not be able to open the vault.

Copied secrets don’t linger.

Sensitive clipboard copies can be cleared automatically. Key cleanup and platform-specific memory protection reduce exposure while Vault is in use.

Open to scrutiny

Read how it works.

The source code, threat model and disclosure policy are public. Vault is still in active development and hasn’t had an independent third-party security audit yet.

Read the security policy

Common questions

Good to know.

Does Vault need a cloud account?

No. The encrypted vault stays on your device and the core features work offline. Optional sync and breach checks need a network connection.

Can I bring my existing passwords?

Yes. Vault has import tools and encrypted backups. Check the current documentation for supported formats, and make a separate backup before moving anything important.

What about signing in and passkeys?

Smart Login starts from an unlocked vault and a saved HTTPS website. It checks the destination and the focused field before filling in or submitting anything. Regular Chromium forms go through the browser integration; Google sign-in on Windows uses the native browser flow. CAPTCHAs, security-key prompts, unknown challenges and extra approvals are up to you, and browser setup may ask you to confirm. See the current release documentation for compatibility. The animation shows a supported GitHub flow, not a live account.

What if someone obtains a copy of the vault file?

The USB binding stays with the encrypted file, even if it’s renamed or copied to another computer. The password isn’t enough: normal unlocking also needs the bound device’s identifier and any key file you’ve set up. That identifier is public and can be spoofed by someone who gets hold of it. Two valid recovery shares are a separate way back in.

What if I lose the bound USB device?

Recovery v2 gives you three shares. Any two different shares from the same active kit can recover the existing local vault file. Store them separately and keep a separate file backup, since recovery can’t bring back a deleted vault. Recovering sets a new password and removes the USB requirement, so afterwards you’ll want to set up a new kit and enroll your device again. USB enrollment currently only works on Windows. It relies on a public device identifier, not a hardware secret that can’t be exported.

Has Vault had an independent security audit?

No, not yet. Vault is in active development and available for evaluation and community review. The security policy covers scope and how to report vulnerabilities.

Explore the project

Have a look.

Read the documentation and release notes before you install. They cover supported platforms, setup and what changed in each version.

In active development and not yet audited by an independent third party. Read the security policy before you try Vault.

02 / More from Yntra

Schedules and teams in one place.Discover Yntra Platform