Security overview

Your vault is encrypted before it leaves your browser

GrailVault is designed so that its server, the people who run it and anyone who steals its database learn nothing useful. This page explains how, and is just as direct about what it cannot protect you from.

How your data is protected

Every credential is encrypted on your device with a key that is built from your master password. The server never receives the password or the key.

  1. Your password becomes a key

    Your browser runs your master password through Argon2id, a deliberately slow, memory-hungry function that makes guessing very expensive. From the result it derives two separate keys: one that protects your vault, and one used only to prove who you are when signing in.

  2. A random vault key encrypts everything

    When you sign up, a random vault key is generated. Every item is encrypted with it using XChaCha20-Poly1305, and each item is bound to your account, its own identity and its type, so items cannot be swapped around or tampered with unnoticed. The vault key itself is stored only in encrypted form.

  3. Changing your password does not re-encrypt your data

    Because your items are protected by the random vault key, a new master password only re-protects that one key. It is quick, and your data is never exposed in the process.

What the server can and cannot see

The server storesThe server never has
Encrypted items (ciphertext)Your master password
Your email addressYour vault key or the keys derived from your password
A slow hash of your login key (not the password)Item names, usernames, websites, tags or notes
Item sizes, kinds and timestampsPasswords, API keys, tokens or any other secret in readable form
Session and activity details: browser, IP address, last activityThe ability to decrypt your vault, even for us

The cryptography

GrailVault uses libsodium, a widely reviewed cryptography library. It does not invent its own algorithms.

PurposeWhat is used
Turning your password into keysArgon2id (128 MiB memory, 3 passes by default)
Encrypting items and the vault keyXChaCha20-Poly1305 with a fresh random nonce each time
Separating the encryption key from the login keylibsodium key derivation with distinct contexts
Storing the login key on the serverArgon2id hash
Two-factor codesTOTP (RFC 6238), with hashed single-use backup codes
Windows Hello, phone and Touch ID unlockWebAuthn with the PRF extension
Recovery key160 random bits, shown once, independent of your password

Protections around your account

  • Two-factor sign-in with an authenticator app, plus backup codes.
  • Device unlock that requires your fingerprint, face or PIN every time, and keeps its secret on your device.
  • Recovery key so a forgotten password does not cost you your data.
  • Sign-in lockout and rate limits that slow down guessing against your account.
  • Session control and activity log: see every signed-in device and end any of them, and review recent sign-ins and wrong-password attempts.
  • A careful browser extension that fills only on the right site, only when you click, and keeps its keys in memory only.
  • A private breach check: only five characters of a one-way fingerprint ever leave your device.
  • Lock on demand: the key lives only in memory and is wiped when you lock, sign out, reload or close the tab.
  • Strict browser protections: a tight content security policy with no inline scripts, secure same-site cookies and request forgery tokens.
  • Encrypted backups you control. A plain CSV export exists for moving to another program, behind a clear warning.

What GrailVault does not protect against

No password manager can promise perfect safety. These are the real limits.

  • A compromised device. Malware or a keylogger on the computer you type your master password into can see what you see.
  • A malicious or hacked server serving altered code. Your browser runs the code the server sends. If an attacker took over our service, they could send code that steals your password the next time you sign in. This is a limit of every web-based vault. We protect the service, and an independent audit is something we want, but it has not happened yet.
  • A weak master password. Argon2id makes guessing expensive, not impossible. Use a long passphrase.
  • Someone using your unlocked screen. The vault stays open while your tab is open, so lock it, or close the tab, on a shared computer.
  • Metadata. We can see your email, how many items you have, their sizes, when they changed, and your activity log.
  • Independent verification. GrailVault has not had a third-party security audit. The design is documented so that you or your own reviewer can check it.
  • A malicious browser extension or malware. Anything running in your browser can see what the browser sees, including a filled-in password. Install only extensions you trust.

Check it yourself

The security documentation goes into more detail, and the limits and roadmap page lists what is not covered.

Found a security problem? Please report it privately to support@grailvault.in.

Private by design, not by promise.

Start with a free trial and keep control of your data.