Home Features Security Pricing FAQ Support
Zero-knowledge

We built it so we can't read it

Your master password never leaves your device. Not at sign-up, not at sign-in, not in a crash report.

AES-256, on your device

Every item is encrypted locally before it's ever written to disk or uploaded anywhere.

600,000-round PBKDF2

Your master password is stretched with PBKDF2-SHA256 at 600,000 iterations before it ever becomes a key — in line with current OWASP guidance.

Stored in Sydney

Encrypted backups live in Google Cloud's australia-southeast1 region. We only ever hold ciphertext we can't open.

k-anonymity breach checks

Checking a password against Have I Been Pwned sends only the first five characters of a SHA-1 hash — never the password, never the full hash.

We don't claim certifications we don't hold. TriPass is not HIPAA-certified, not SOC 2 or ISO 27001 audited, and is not currently built for the EU (GDPR) market. What we actually do is laid out in full in the Privacy Policy.

How recovery works

No password reset, by design

There's no "forgot password" email, because we never hold a copy or a key that could reset it for you. At sign-up you're shown a one-time, 25-character Recovery Kit code — that code, not an email link, is the actual way back in if you lose your master password. Lose both the master password and the Recovery Kit, and the vault can't be recovered. That's what zero-knowledge means in practice, not just as a marketing word.

Free or Premium, the encryption doesn't change.

Security isn't a paid feature here.

See plans