Skip to main content
MicaraVault

Your secrets are encrypted before they leave your device.

Passwords, API credentials, SSH keys, certificates and sensitive files — encrypted on your device with keys we never receive. A breach of our servers hands an attacker ciphertext, not your secrets.

We do not claim to be unhackable — no system is. Here is exactly what we cannot protect you from.

item templates, logins to Java keystores
18
of memory per Argon2id derivation, on your device
64MiB
nonces — random is safe, no counter state
192-bit
of IP retention on security events. Then gone.
90days

What “zero-knowledge” actually means

Not a slogan — a specific division of what we hold and what we do not. Both halves are published.

Never leaves your device

  • Your master password
  • The keys derived from it
  • Your account private keys, unencrypted
  • Passwords, notes, API keys, private keys
  • File contents, filenames and file types

What our servers do see

  • Your email address and account timestamps
  • How many vaults and items you have, and their type
  • Ciphertext sizes and revision numbers
  • IP addresses on security events, for 90 days
  • Who you share with (not what)

A real, deliberate exposure. We publish it in full rather than burying it — read the security architecture.

Built for the credentials engineers actually hold

Not just website logins. Key material gets its own handling: encrypted filenames, no automatic preview, a download permission separate from viewing, and an audit event every time.

Logins & passkeys

Usernames, passwords, one-time codes, and encrypted version history for every change.

API credentials

Keys, secrets, tokens, endpoints, scopes, expiry and rotation reminders.

SSH & server access

Private keys, passphrases, fingerprints, host associations, rotation tracking.

Certificates & keystores

.pem, .crt, .jks, .p12 and .pfx — parsed locally, never by our servers.

Database & environment

Connection strings and .env variables, each variable copyable on its own.

Identity, cards, licences

Documents, payment cards and recovery codes, all masked by default.

What you get today

Shipped and working, not planned. Where something is not built yet, it is listed further down rather than implied here.

Every item type, editable

Eighteen templates from logins to Java keystores, each with the right fields, masking and generators.

Encrypted file attachments

Uploaded in chunks, each one authenticated. Filenames are encrypted too, and key material is never previewed.

Password health

Weak, reused and expiring credentials, plus a breach check that sends only a five-character hash prefix.

Security centre

A score where every point is explained and every gap tells you what to do about it. Devices and sessions, revocable.

Activity log

Hash-chained and append-only, with verification you can run yourself — and an honest note on what that check cannot prove.

Sharing

To a person, sealed to their verified key; or by link, where the decryption key rides in the URL fragment and never reaches us.

Generators

Passwords, passphrases, API keys, tokens and recovery codes, with entropy reported from the real character pool.

Export and trash

Local export in encrypted or plain form. Deleting destroys the key, which is what makes deletion final.

Two-factor and recovery

Authenticator apps, single-use recovery codes, trusted devices, and an Emergency Kit generated on your device.

Sign in by email link

A one-time link signs you in without your password — and then still asks for it, because signing in and decrypting are different things here.

Not built yet

Importing from another password manager, the browser extension and autofill, mobile and desktop apps, and the organisation administration screens. The organisation permissions and policy engine exist and are tested behind the API — the screens for them are not written.

MicaraVault also has not yet been through independent penetration testing or cryptographic review, so it is not ready to hold credentials you cannot afford to lose.

The engineering, stated plainly

  1. 1

    Keys are derived on your device

    A memory-hard function turns your master password into keys, tuned so guessing is expensive. The cost can be raised later without re-encrypting anything you have stored.

  2. 2

    Signing in never sends a password

    Not even a hash. Your device signs a challenge with a key derived separately from the one that decrypts your vault, so authenticating and decrypting stay independent.

  3. 3

    Every item has its own key

    Sharing hands over one key. Rotating a vault rewraps small keys instead of re-encrypting gigabytes. A leak is contained to what it actually covers.

  4. 4

    Files are verified before they are saved

    Encrypted in chunks, each authenticated and bound to its position, so truncating, reordering or splicing a file is detected rather than silently accepted.

  5. 5

    Deleting destroys keys

    Purged data cannot be decrypted afterwards — including from a backup copy that has not yet rotated out. Key destruction is the guarantee, not a promise to chase bytes.

Start with a personal vault

Free for personal use. Your Emergency Kit is generated on your device during signup — we never see it.

Create a vault