Zero-knowledge by design

Your passwords, unreadable to everyone but you

PassKrypt encrypts your vault on your own devices before it ever reaches our servers. We store ciphertext we genuinely cannot read — not our staff, not our infrastructure, not anyone who breaches it.

No credit card required · Cancel any time · Your data stays yours

AES-256-GCM, encrypted on your device Secret Key — your password alone is not enough Hosted in the EU No trackers, no analytics, no ads
Everything you need

A password manager that gets out of your way

Organise thousands of credentials, share nothing you did not mean to, and find anything in a keystroke.

Vaults & nested folders

Separate personal from work, nest folders as deep as you like, and colour-code anything. Drag entries and whole folders between vaults.

Search that actually finds it

One keystroke searches every vault, folder and entry at once, with the full path shown so you know where a result lives.

Built-in 2FA codes

Store TOTP secrets alongside the login and copy the current code with a live countdown — no second app to reach for.

Security dashboard

A health score across every vault: weak passwords, reused ones, credentials going stale, and logins still missing 2FA.

Any kind of secret

Logins, cards, secure notes, SSH keys, databases, identities — or design your own entry type with exactly the fields you need.

Import and export, freely

Bring your vault from 1Password, CSV or JSON. Export whenever you want — including after a trial ends. Your data is never held hostage.

How it works

Two secrets, and neither one reaches us

Your Account Password and your Secret Key are combined on your device to derive the key that unlocks your vault. That key is never transmitted.

YOUR DEVICE Account Password you remember it Secret Key 125 bits, on your device Master key never transmitted AES-256-GCM encrypt ciphertext only PassKrypt server stores a blob it cannot decrypt
Two independent secrets, combined only on your hardware.

What we can see

Your email address, your plan, when you last synced, and the size of your encrypted blob. That is the complete list — it is what running the service requires.

What we cannot see

Every password, note, card, attachment and entry title. All of it is encrypted before it leaves your device. We cannot read it, reset it, or hand it to anyone who asks.

Honest about the trade-off. Because we hold no keys, support genuinely cannot recover your data. If you lose your Account Password, your Secret Key and your Recovery Key, it is gone. That is the cost of a design where a breach of our servers tells an attacker nothing — and it is why we hand you a Recovery Kit on day one.

Read the full security model →

Get PassKrypt

Install it where you work

The desktop app keeps an encrypted copy on your machine, so your vault opens instantly and still works offline.

Windows

Windows 10 and 11 · 64-bit installer

Coming soon

Web app

Available now · any modern browser · nothing to install

Open web vault

macOS

In development

Coming soon

Linux

AppImage in development

Coming soon
About the desktop builds

Desktop installers are in preparation. The web app above is the full client and is available today — it runs the same code and stores nothing on the server it could read.

Pricing

Start free for 14 days

No card up front. If PassKrypt is not for you, your data is still yours to export.

Free trial

€0

Full access for 14 days, no payment details required.

  • Every Personal feature
  • Unlimited entries
  • Sync across your devices
  • Export your data any time
Start free

Family & Team

Soon

Shared vaults, roles and admin controls. In development.

  • Shared vaults
  • Roles and permissions
  • Central admin console
Not yet available

Prices exclude VAT, which is shown at checkout based on your country. Cancel any time.

Questions

Straight answers

Use the Recovery Key from your Recovery Kit. It resets your password and issues a new Secret Key without losing a single entry. If you have lost the Kit as well as your password, nobody — including us — can restore the vault. Print the Kit.

Because passwords are guessable and 125 random bits are not. If our database were ever stolen, an attacker could try to brute-force weak passwords. Mixing in a Secret Key that only exists on your devices makes that pointless.

Nothing is deleted. You keep full read access to every entry, and you can export your whole vault at any time. Syncing new changes needs a subscription — your data does not.

Yes. The desktop app keeps an encrypted copy on your machine. You can unlock and use your vault with no connection; changes sync when you are back online.

No. This site loads no third-party scripts, sets no advertising or analytics cookies, and makes no requests to any other domain. That is why there is no cookie banner.

On servers in the European Union (Frankfurt). Since everything is encrypted before it arrives, the location matters less than usual — but it keeps your account data under EU jurisdiction.

Import a 1Password .1pux export, or a CSV or JSON file from most other managers. Vaults and folders are recreated as they were, not flattened into one pile.

Take your passwords back

Fourteen days, every feature, no card. Keep it or export everything and walk away.