Client-side encryption
PBKDF2-SHA-256 protects a random vault key and AES-256-GCM encrypts each item before upload.
A separate master password derives browser-only keys so the server stores ciphertext rather than your vault contents.
PBKDF2-SHA-256 protects a random vault key and AES-256-GCM encrypts each item before upload.
Store logins, secure notes, cards, identities, Wi-Fi credentials and software licences.
Generate strong passwords and review weak or reused passwords without sending secrets away.
KMAIL and administrators cannot recover a forgotten master password or inspect decrypted items.
Sharing and attachments remain disabled until complete reviewed end-to-end designs are available.