Zero-Knowledge • Offline-First • Privacy by Design

Keep your payment cards & credentials
securely on your device.

Most apps upload your financial data and passwords to corporate cloud servers. The Vault doesn't. We built The Vault to be a 100% offline personal card and credential manager, protected by robust AES-256 encryption. Your data is truly yours.

•••• •••• •••• 4242
Card Holder
ALEXANDER DOE
Expires
12/28

Why We Built The Vault

Traditional password managers introduce risks by centralizing sensitive credentials in corporate databases. The Vault solves this through self-custody and local zero-knowledge cryptography.

Traditional Cloud Managers

The Centralized Cloud Dilemma

Cloud password services store millions of users' encrypted databases on their corporate servers. A single backend breach, server vulnerability, or misconfiguration exposes everyone.

✗Data stored permanently on external corporate servers
✗High-value target for hackers, breaches, and data leaks
✗Continuous online network connectivity required
✗Third-party corporate custodians hold your encrypted records
The Vault Solution

Zero-Knowledge Self-Custody

The Vault operates locally on your device hardware. All payment cards, credentials, notes, and attachments are encrypted using AES-256-GCM with keys derived from your master password. Zero centralized servers.

✓100% offline-first local database on your own device
✓Military-grade AES-256-GCM encryption at rest
✓Strong cryptographic keys derived solely on your hardware
✓Optional user-controlled encrypted backups via Google Drive

Why The Vault Integrates with Google Drive & iCloud

We believe in total transparency. Here is exactly why The Vault offers optional Google OAuth 2.0 and Apple iCloud sync, what permissions are requested, and how your privacy is protected.

Disaster Recovery & Sync

To protect you against device damage, loss, or phone upgrades, The Vault offers optional cross-device synchronization to your personal Google Drive or Apple iCloud account.

Encrypted Before Upload

Your backup archive is fully encrypted on your phone using AES-256-GCM with your master password before it leaves your device. Google and Apple receive only an unreadable ciphertext blob.

Strict Minimal Scope

The Vault authenticates via Google OAuth 2.0 and strictly requests access only to its dedicated App Data folder (drive.appdata / drive.file). The Vault cannot access your other Google Drive files.

Strict Compliance with Google Limited Use Policy

The Vault's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We never sell your Google data, never share it with third parties, never use it for targeted advertising, and never use it to train AI models.

Everything You Need to Protect Your Data

Built from the ground up for speed, offline reliability, and uncompromised cryptographic protection.

Military-Grade AES-256-GCM

All card details, credentials, and attachments are encrypted locally using AES-256-GCM authenticated encryption with strong on-device key derivation. The gold standard in cryptography.

Biometric Authentication

Seamlessly unlock your vault using Face ID, Touch ID, or Android Biometrics. Biometric authentication is handled by your device's hardware Secure Enclave without exposing templates.

100% Offline Architecture

Zero mandatory network transmission. All sensitive data is stored securely on your local device. No corporate databases, no remote tracking, and no external points of failure.

Encrypted Cloud Backups

Create encrypted backups of your vault and safely sync them to your personal Google Drive (via OAuth 2.0) or Apple iCloud for seamless recovery when switching devices.

Smart Scan

Quickly capture card details via camera. Ephemeral AI-powered extraction with zero data retention—scanned images are never stored, never cached, and never used to train AI models.

Privacy & Analytics Control

Full control over your telemetry. You can disable Google Analytics directly during the initial sign-up flow or toggle it off anytime in Settings. Analytics never touches your vault records.

Smart Vault Organization

Organize payment cards, login credentials, secure notes, and photo attachments with custom categories, tags, and rapid search capabilities.

Zero-Knowledge Self-Custody

You are the sole custodian of your master password and encryption keys. We have no master keys, no recovery backdoors, and no access to your confidential information.

How Your Data Stays Protected

From data entry to local storage and optional cloud backup, encryption is enforced at every layer.

01

Data Input

You add payment cards, passwords, or notes inside the app. No data is transmitted over the internet.

02

On-Device Derivation

Cryptographic encryption keys are derived on-device from your unique master password.

03

AES-256-GCM Storage

Data is encrypted and stored in local sandboxed storage. Plaintext records never touch persistent disk.

04

Optional Cloud Backup

When initiated, an encrypted backup blob is sent over TLS directly to your Google Drive App Data folder.

Frequently Asked Questions

Everything you need to know about The Vault's security model, offline architecture, and Google Drive integration.

The Vault is a zero-knowledge, offline-first personal credential and payment card manager. Its purpose is to give you complete self-custody over your sensitive payment cards, credentials, notes, and digital records by keeping them securely encrypted on your own device, rather than trusting third-party corporate cloud servers.