Here is exactly how, and where it stops.
TriPass is built and in testing. It is not on the App Store yet. Everything on this page describes the current pre-release build.
A login, a card, a 2FA code.
AES-256-GCM, with a random 256-bit key kept in the iOS Keychain.
If you back up, our server receives data it has no key for.
PBKDF2-SHA256. 600,000 rounds for new accounts’ backup key.
Sign-in uses a separate one-way value, not the key to your vault.
Only 5 characters of a SHA-1 hash leave the phone.
Your Recovery Kit is the only way back in. We can’t reset what we can’t read.
Face ID or passcode, plus screenshot and screen-recording protection.
No account? Nothing ever leaves your phone.
Older accounts use 210,000 PBKDF2 rounds, as do the on-device key wrap and the sign-in credential. Where data is held
Only if you create an account.
| What | Can we read it? |
|---|---|
| Your email address | Yes |
| Salt, iteration count, verifier | Yes, but they open nothing |
| Sign-in credential (derived, not your password) | Firebase stores it |
| Backup key wrapped under your Recovery Kit | No |
| Your encrypted vault (backup) | No |
Anonymous events, never vault contents. On by default; off in Settings.
Stack traces, never your data. On by default; off in Settings.
Off by default. If on, the logo provider sees which sites you use.
These panels use your browser's built-in Web Crypto with the same algorithms and parameters as the app. This is not the app's code, but it does the same maths.
PBKDF2-SHA256 at 600,000 iterations with a random salt derives the key. AES-256-GCM encrypts the note. Nothing is sent anywhere.
Your browser hashes the password with SHA-1 and sends only the first 5 characters to Have I Been Pwned, which returns every breached hash starting with them. The match happens here. This is the method the app uses (k-anonymity).
Sending 5 characters keeps the password itself private. The request still reveals that someone checked a password with that prefix. In the app, breach checks are part of Premium.
A quick estimate from length, character variety, repeats and common words. It is a rule of thumb written for this page, not the app’s Password Health scoring and not a crack-time guarantee. Nothing is sent.
No independent audit yet, and no certifications claimed. What we do is set out in full in the Privacy Policy.