One vault for the household
Invite family members into a shared vault. Everyone unlocks the same encrypted secrets with their own master password, and it stays zero-knowledge on our side.
Zero-knowledge encryption on your device, plus family vaults, business secret folders and authenticator links you can share safely.
AES-256-GCM · PBKDF2 600K · Open crypto contract
Share without giving up control
Keep your personal secrets alone, share a household vault, or hand teammates only the folders they need to get started.
Invite family members into a shared vault. Everyone unlocks the same encrypted secrets with their own master password, and it stays zero-knowledge on our side.
Create folders for onboarding or projects, drop in passwords and secrets, then assign members. Admins control what’s added or removed; members view only.
Send a rotating TOTP code to someone without a VaultKeep account. Protect it with an auth code, set an expiry, and revoke it at any time.
Business onboarding
Admins create folders, assign members, and manage passwords. Members unlock the org vault and get a view-only list of what they were given, which is all a first day needs without spreading edit rights.
Engineering onboarding
Encrypted with the org key · members cannot edit
Designed around one rule: the server must never be able to read your secrets.
Your master password never leaves your device. Everything is encrypted locally with AES-256-GCM and 600,000 PBKDF2 rounds. The server only ever stores ciphertext it cannot read.
Unlock with Face ID, Touch ID, Windows Hello or a security key. Your passkey derives the key that opens the vault, so there is no master password to type.
The browser extension saves new logins as you sign up and offers matching ones on the page. Press Alt or Option plus V to call it up, and filter by typing.
Web app, installable desktop app, Chrome and Firefox extension, iPhone and Android. One vault and one encryption contract everywhere.
TOTP codes live beside your passwords. Import by QR or otpauth link, bring codes over from Google Authenticator, and restore deleted ones from a 90 day trash.
Store the one-time recovery codes every service hands you, mark them used as you go, and keep them encrypted with the rest of your vault.
Find weak, reused and expired passwords at a glance. Breach checking uses k-anonymity, so only the first five characters of a hash ever leave your device.
Build long random passwords or readable passphrases, skip ambiguous characters, and save straight into the vault.
A one-time recovery key is generated at signup. It is the only way back in if you forget your master password, and resetting rotates it automatically.
Also from VaultKeep
Silence spam before your phone even rings. Block numbers and whole prefixes, reject hidden and unknown callers, and keep an encrypted copy of your block list in your VaultKeep account.
Create a free vault, invite family when you’re ready, or spin up a business org with secret folders for onboarding.