Skip to main content
MicaraVault

Your secrets are encrypted before they leave your device.

Passwords, API credentials, SSH keys, certificates and sensitive files — encrypted on your device with keys we never receive. A breach of our servers hands an attacker ciphertext, not your secrets.

We do not claim to be unhackable — no system is. Here is exactly what we cannot protect you from.

What “zero-knowledge” actually means

Not a slogan — a specific division of what we hold and what we do not. Both halves are published.

Never leaves your device

  • Your master password
  • The keys derived from it
  • Your account private keys, unencrypted
  • Passwords, notes, API keys, private keys
  • File contents, filenames and file types

What our servers do see

  • Your email address and account timestamps
  • How many vaults and items you have, and their type
  • Ciphertext sizes and revision numbers
  • IP addresses on security events, for 90 days
  • Who you share with (not what)

A real, deliberate exposure. We publish it in full rather than burying it — read the security architecture.

Built for the credentials engineers actually hold

Not just website logins. Key material gets its own handling: encrypted filenames, no automatic preview, a download permission separate from viewing, and an audit event every time.

Logins & passkeys

Usernames, passwords, one-time codes, password history and autofill rules.

API credentials

Keys, secrets, tokens, endpoints, scopes, expiry and rotation reminders.

SSH & server access

Private keys, passphrases, fingerprints, host associations, rotation tracking.

Certificates & keystores

.pem, .crt, .jks, .p12 and .pfx — parsed locally, never by our servers.

Database & environment

Connection strings and .env variables, each variable copyable on its own.

Identity, cards, licences

Documents, payment cards and recovery codes, all masked by default.

The engineering, stated plainly

  1. 1

    Keys are derived on your device

    A memory-hard function turns your master password into keys, tuned so guessing is expensive. The cost can be raised later without re-encrypting anything you have stored.

  2. 2

    Signing in never sends a password

    Not even a hash. Your device signs a challenge with a key derived separately from the one that decrypts your vault, so authenticating and decrypting stay independent.

  3. 3

    Every item has its own key

    Sharing hands over one key. Rotating a vault rewraps small keys instead of re-encrypting gigabytes. A leak is contained to what it actually covers.

  4. 4

    Files are verified before they are saved

    Encrypted in chunks, each authenticated and bound to its position, so truncating, reordering or splicing a file is detected rather than silently accepted.

  5. 5

    Deleting destroys keys

    Purged data cannot be decrypted afterwards — including from a backup copy that has not yet rotated out. Key destruction is the guarantee, not a promise to chase bytes.

Start with a personal vault

Free for personal use. Your Emergency Kit is generated on your device during signup — we never see it.

Create a vault