Skip to main content
Everything is encrypted locally and your master password never leaves the browser. So heads up: forget it and the entries are gone for good.
PlusSecurity

Password Vault

All your credentials in one place, encrypted with AES-256-GCM right in your browser. Only your head knows the master password - it is never stored and never transmitted. With a security audit, password generator, auto-lock and import from LastPass, Bitwarden and KeePass.

A look inside

SecurityPassword VaultFictional demo | Plus
Protected
Privacy control

Zero-knowledge architecture

1Zero-knowledge architecture
2AES-256-GCM + PBKDF2
3Security audit
4Import from other managers
Read-only preview. Open the tool to use it.

This safe preview shows what the tool is for without running account-only actions.

What Password Vault does

A password manager is only as trustworthy as its architecture. That is why the Passwort-Tresor is built strictly zero-knowledge: every entry is encrypted on your device before it is stored anywhere. Encryption runs through your browser Web Crypto API with AES-256-GCM, and the key is derived from your master password via PBKDF2 with 1,000,000 iterations. Your passwords exist in plain text only in the moment you look at them.

The master password never leaves your device. It is not stored, not transmitted, not hashed and kept anywhere - it is used solely to derive the key locally. The honest flip side: if you forget it, nobody can reset it. No support, no reset link, not even us. That is the whole point of the architecture: what we do not know, we cannot lose or hand over.

In daily use the vault behaves like a tidy desk. Entries have a title, username, password, URL and notes, can be sorted into categories, marked as favorites and searched. The built-in generator creates strong passwords right when you add an entry, removing the classic excuse of not being able to think of one.

The security audit shows you where it hurts: weak passwords, reused passwords and entries that have not been changed in ages. That is how you work off the legacy from the era when the same password with an exclamation mark at the end was used everywhere.

Switching over does not mean starting from zero: CSV exports from LastPass, Bitwarden and KeePass import directly. In the other direction you create an encrypted JSON export as a backup - and even that leaves your device only as ciphertext.

For everyday protection there are the mechanisms you only miss once they are gone: auto-lock after a configurable idle time (5 to 60 minutes or never), and copied passwords are automatically removed from the clipboard after 30 seconds. An open vault on an unattended computer remains a risk though - even the best encryption does not protect against the colleague walking past your unlocked screen.

Features

Zero-knowledge architecture

Encryption and decryption happen exclusively on your device. Only ciphertext is ever stored.

AES-256-GCM + PBKDF2

Web Crypto API with AES-256-GCM, key derivation via PBKDF2 with 1,000,000 iterations and SHA-256.

Security audit

Spots weak, reused and long-unchanged passwords at a glance.

Import from other managers

CSV import from LastPass, Bitwarden and KeePass - switching takes minutes, not evenings.

Encrypted export

Backup as an encrypted JSON file - even the export leaves your device only as ciphertext.

Auto-lock

The vault locks itself after a configurable idle period - 5, 15, 30 or 60 minutes.

Clipboard self-clears

Copied passwords are automatically removed from the clipboard after 30 seconds.

Organisation built in

Categories, favorites, search and an integrated password generator right where you add entries.

How it works

  1. 1

    Create your vault

    Choose a strong master password - ideally a long passphrase. It is the only key and cannot be reset.

  2. 2

    Add or import entries

    Add credentials one by one or import the CSV export from LastPass, Bitwarden or KeePass.

  3. 3

    Work through the audit

    Open the security audit and replace weak and duplicate passwords with the built-in generator.

  4. 4

    Daily use: copy and let it lock

    Copy passwords as needed - the clipboard clears after 30 seconds and the vault locks itself when idle.

Who needs this

Anyone who finally wants their passwords out of the notes app and browser plain text.
Switchers from LastPass, Bitwarden or KeePass looking for a zero-knowledge alternative.
Users who want to clean up weak and duplicate passwords via the security audit.
Freelancers keeping client logins and credentials organised and encrypted.
Anyone who cares that the provider is technically unable to read their passwords.

Frequently asked questions

What exactly does zero-knowledge mean?

All entries are encrypted and decrypted on your device. Only ciphertext is ever stored, and the master password never leaves your device. Nobody but you can read the contents - not even us. No software can promise absolute security, but the architecture ensures there simply is no plain-text copy of your passwords outside your device.

What happens if I forget my master password?

Then the data is gone - honestly and irrecoverably. There is no reset and no backdoor, because the master password is not stored anywhere. That is exactly where the vault gets its trustworthiness from. So pick a memorable passphrase and keep an encrypted export as a backup.

Can I migrate from LastPass, Bitwarden or KeePass?

Yes. Export your entries there as CSV and import the file into the vault. Entries are encrypted locally the moment they are imported. Afterwards you should delete the unencrypted CSV file - it is the only plain-text intermediate step.

What encryption is used?

AES-256-GCM via your browser Web Crypto API. The key is derived from your master password via PBKDF2 with 1,000,000 iterations and SHA-256. These are established, openly documented standards - no home-grown crypto.

Does a copied password linger in the clipboard?

No. Copied passwords are removed from the clipboard automatically after 30 seconds so they do not get pasted somewhere by accident. On top of that, the vault locks itself after a configurable idle period.

Password Generator

Generate cryptographically secure passwords and passphrases. Customize length and character s…

Password Expiry Calendar

Track password expiry dates and get automatic calendar reminders. ICS export for Apple Calend…

Hash Verify

Calculate MD5, SHA-1, SHA-256, SHA-384, SHA-512 hashes and HMAC. Hash files and text, verify…

Email Encryption

Encrypt and decrypt messages with RSA-OAEP + AES-256-GCM. Key pair generation, digital signat…

Ready to use Password Vault?

No installation. Included from Plus. Open it right in your browser.

Open now