Void Vault
Zero-knowledge by design

Your secrets, encrypted before they ever leave your device.

Void Vault is a password manager where encryption happens entirely in your browser. Our servers only ever store ciphertext — we couldn't read your vault even if we wanted to.

  • AES-256-GCM
  • Argon2id
  • Zero-knowledge

What the server sees

Nothing readable. Ever.

Encrypted

encryptedTitle

U2FsdGVkX1+9vQm…r7Fz0aQ=

encryptedData

m9W3kF…c2V0aWQgYSBzZWNyZXQgaXMgbm8=…8fL2xP

iv

a1b2c3d4e5f6…

authTag

f6e5d4c3b2a1…

Security isn't a feature. It's the foundation.

Every layer of Void Vault is built around one principle: if we can't see your data, neither can anyone who breaches us.

Zero-knowledge architecture

Your master password never leaves your device. Keys are derived locally, so only you can ever decrypt your vault.

AES-256-GCM encryption

Every vault item is sealed with authenticated encryption — confidentiality and tamper detection in a single primitive.

Two-factor authentication

Protect your account with TOTP authenticators and hardware keys, plus one-time recovery codes for emergencies.

Organized, encrypted folders

Group logins into folders whose names are encrypted too. Structure is yours alone — not metadata we can mine.

Full audit trail

An append-only log of sign-ins and vault activity keeps you informed about everything that touches your account.

Session control

Refresh-token rotation with device context lets you see active sessions and revoke access from anywhere, instantly.

How zero-knowledge works

Three steps stand between your secrets and everyone else — including us.

  1. 01

    Derive your key locally

    Your master password is stretched into an encryption key with Argon2id — right in your browser. It is never transmitted or stored.

  2. 02

    Encrypt on your device

    Each vault item is sealed with AES-256-GCM before sync. Titles, passwords, notes — all ciphertext before they hit the network.

  3. 03

    Sync ciphertext only

    Our servers store encrypted blobs, IVs, and auth tags. Even with full database access, an attacker gets unreadable noise.

Trust nothing, verify everything

A breach of our servers exposes nothing.

Zero-knowledge isn't a marketing claim — it's an architecture. With no plaintext and no keys on our side, the worst-case scenario for us is a non-event for you.

  • Master password never transmitted or stored
  • Encryption keys derived and held only on your device
  • Argon2id key derivation with OWASP-aligned parameters
  • Authenticated encryption (AES-256-GCM) for every vault item
  • Rotating refresh tokens with per-session revocation
  • Append-only audit log for every security-relevant event

Take back control of your credentials.

Create your vault in under a minute. Your master password is the only key — and it stays with you.