Your master password never leaves your device. Not at sign-up, not at sign-in, not in a crash report.
Every item is encrypted locally before it's ever written to disk or uploaded anywhere.
Your master password is stretched with PBKDF2-SHA256 at 600,000 iterations before it ever becomes a key — in line with current OWASP guidance.
Encrypted backups live in Google Cloud's australia-southeast1 region. We only ever hold ciphertext we can't open.
Checking a password against Have I Been Pwned sends only the first five characters of a SHA-1 hash — never the password, never the full hash.
We don't claim certifications we don't hold. TriPass is not HIPAA-certified, not SOC 2 or ISO 27001 audited, and is not currently built for the EU (GDPR) market. What we actually do is laid out in full in the Privacy Policy.
There's no "forgot password" email, because we never hold a copy or a key that could reset it for you. At sign-up you're shown a one-time, 25-character Recovery Kit code — that code, not an email link, is the actual way back in if you lose your master password. Lose both the master password and the Recovery Kit, and the vault can't be recovered. That's what zero-knowledge means in practice, not just as a marketing word.