Security

Built so that nobody but you can read it.

Not Google. Not us. Not anyone who steals a file. Here’s exactly how Secure It protects your vault.

How your vault is encrypted

  1. STEP 1

    Master password

    Never stored, never sent anywhere.

  2. STEP 2

    Argon2id

    Turns it into a key. Memory-hard: slow for attackers, instant for you.

  3. STEP 3

    AES-256-GCM

    Encrypts the whole vault on your device.

  4. STEP 4

    Your Google Drive

    Stores only the encrypted vault.enc file.

AES-256-GCMARGON2IDBIP-39 RECOVERYON-DEVICE ONLY

What that means

Six promises, by design.

No servers

We don’t run a backend that stores user data. There is no account database to breach.

Zero-knowledge

Encryption and decryption happen only on your devices. Google stores gibberish; we never see anything.

Least-privilege Drive access

The app uses the drive.file scope: it can only see files it created — never the rest of your Drive.

Protected actions

Revealing a password needs your fingerprint, and it hides again after 15 seconds.

Clipboard auto-wipe

Copied passwords are cleared from the clipboard after 45 seconds.

Recovery you control

A 12-word recovery phrase and an Emergency Kit PDF with an offline recovery script.

The trade-off of zero-knowledge

Because we never hold your key, we can’t reset your master password for you. Keep your 12-word recovery phrase and Emergency Kit somewhere safe — they’re the only way back in if you forget it.

Read the privacy policy →