Home Features Security Scanner Pricing FAQ Support Accounts
Security

Built so we can’t read your vault

Here is exactly how, and where it stops.

TriPass is built and in testing. It is not on the App Store yet. Everything on this page describes the current pre-release build.

How it works

1

You save something

A login, a card, a 2FA code.

2

It’s sealed on your iPhone

AES-256-GCM, with a random 256-bit key kept in the iOS Keychain.

3

Only ciphertext leaves

If you back up, our server receives data it has no key for.

The essentials

Keys from your master password

PBKDF2-SHA256. 600,000 rounds for new accounts’ backup key.

Your password is never sent

Sign-in uses a separate one-way value, not the key to your vault.

Private breach checks

Only 5 characters of a SHA-1 hash leave the phone.

No reset, by design

Your Recovery Kit is the only way back in. We can’t reset what we can’t read.

Locked when you’re not looking

Face ID or passcode, plus screenshot and screen-recording protection.

Account optional

No account? Nothing ever leaves your phone.

Older accounts use 210,000 PBKDF2 rounds, as do the on-device key wrap and the sign-in credential. Where data is held

What our server holds

Only if you create an account.

WhatCan we read it?
Your email addressYes
Salt, iteration count, verifierYes, but they open nothing
Sign-in credential (derived, not your password)Firebase stores it
Backup key wrapped under your Recovery KitNo
Your encrypted vault (backup)No

Where it stops protecting you

A weak master passwordA stolen database lets guesses run offline. Use a long passphrase.
A compromised phoneJailbroken or infected devices are out of our reach.
Losing both keysNo master password and no Recovery Kit means no way back in.
Breach-check requestsThe 5 characters show a check happened, not which password.

Other data, in plain sight

Usage analytics

Anonymous events, never vault contents. On by default; off in Settings.

Crash reports

Stack traces, never your data. On by default; off in Settings.

Site logos

Off by default. If on, the logo provider sees which sites you use.

Don't take our word for it

Run the crypto
yourself.

These panels use your browser's built-in Web Crypto with the same algorithms and parameters as the app. This is not the app's code, but it does the same maths.

Demo 01 · runs entirely in this tab

Encrypt it like TriPass does

PBKDF2-SHA256 at 600,000 iterations with a random salt derives the key. AES-256-GCM encrypts the note. Nothing is sent anywhere.

Key derivationnot run yet
Salt-
Nonce-
What a server would store-
Encrypt something first.
Demo 02 · sends 5 characters

Has this password been breached?

Your browser hashes the password with SHA-1 and sends only the first 5 characters to Have I Been Pwned, which returns every breached hash starting with them. The match happens here. This is the method the app uses (k-anonymity).

SHA-1 (computed here)-
Sent to api.pwnedpasswords.com-
Result-

Sending 5 characters keeps the password itself private. The request still reveals that someone checked a password with that prefix. In the app, breach checks are part of Premium.

Demo 03 · runs entirely in this tab

Rough password strength

A quick estimate from length, character variety, repeats and common words. It is a rule of thumb written for this page, not the app’s Password Health scoring and not a crack-time guarantee. Nothing is sent.

Type to see a rough estimate
Random characters, shown to illustrate scrambling. This is not encryption; Demo 01 is.
Nothing typed here ever leaves your browser.

No independent audit yet, and no certifications claimed. What we do is set out in full in the Privacy Policy.

Free or Premium, the lock is the same.

Security isn’t a paid feature here.