Security overview
Your vault is encrypted before it leaves your browser
GrailVault is designed so that its server, the people who run it and anyone who steals its database learn nothing useful. This page explains how, and is just as direct about what it cannot protect you from.
How your data is protected
Every credential is encrypted on your device with a key that is built from your master password. The server never receives the password or the key.
-
Your password becomes a key
Your browser runs your master password through Argon2id, a deliberately slow, memory-hungry function that makes guessing very expensive. From the result it derives two separate keys: one that protects your vault, and one used only to prove who you are when signing in.
-
A random vault key encrypts everything
When you sign up, a random vault key is generated. Every item is encrypted with it using XChaCha20-Poly1305, and each item is bound to your account, its own identity and its type, so items cannot be swapped around or tampered with unnoticed. The vault key itself is stored only in encrypted form.
-
Changing your password does not re-encrypt your data
Because your items are protected by the random vault key, a new master password only re-protects that one key. It is quick, and your data is never exposed in the process.
What the server can and cannot see
| The server stores | The server never has |
|---|---|
| Encrypted items (ciphertext) | Your master password |
| Your email address | Your vault key or the keys derived from your password |
| A slow hash of your login key (not the password) | Item names, usernames, websites, tags or notes |
| Item sizes, kinds and timestamps | Passwords, API keys, tokens or any other secret in readable form |
| Session and activity details: browser, IP address, last activity | The ability to decrypt your vault, even for us |
The cryptography
GrailVault uses libsodium, a widely reviewed cryptography library. It does not invent its own algorithms.
| Purpose | What is used |
|---|---|
| Turning your password into keys | Argon2id (128 MiB memory, 3 passes by default) |
| Encrypting items and the vault key | XChaCha20-Poly1305 with a fresh random nonce each time |
| Separating the encryption key from the login key | libsodium key derivation with distinct contexts |
| Storing the login key on the server | Argon2id hash |
| Two-factor codes | TOTP (RFC 6238), with hashed single-use backup codes |
| Windows Hello, phone and Touch ID unlock | WebAuthn with the PRF extension |
| Recovery key | 160 random bits, shown once, independent of your password |
Protections around your account
- Two-factor sign-in with an authenticator app, plus backup codes.
- Device unlock that requires your fingerprint, face or PIN every time, and keeps its secret on your device.
- Recovery key so a forgotten password does not cost you your data.
- Sign-in lockout and rate limits that slow down guessing against your account.
- Session control and activity log: see every signed-in device and end any of them, and review recent sign-ins and wrong-password attempts.
- A careful browser extension that fills only on the right site, only when you click, and keeps its keys in memory only.
- A private breach check: only five characters of a one-way fingerprint ever leave your device.
- Lock on demand: the key lives only in memory and is wiped when you lock, sign out, reload or close the tab.
- Strict browser protections: a tight content security policy with no inline scripts, secure same-site cookies and request forgery tokens.
- Encrypted backups you control. A plain CSV export exists for moving to another program, behind a clear warning.
What GrailVault does not protect against
No password manager can promise perfect safety. These are the real limits.
- A compromised device. Malware or a keylogger on the computer you type your master password into can see what you see.
- A malicious or hacked server serving altered code. Your browser runs the code the server sends. If an attacker took over our service, they could send code that steals your password the next time you sign in. This is a limit of every web-based vault. We protect the service, and an independent audit is something we want, but it has not happened yet.
- A weak master password. Argon2id makes guessing expensive, not impossible. Use a long passphrase.
- Someone using your unlocked screen. The vault stays open while your tab is open, so lock it, or close the tab, on a shared computer.
- Metadata. We can see your email, how many items you have, their sizes, when they changed, and your activity log.
- Independent verification. GrailVault has not had a third-party security audit. The design is documented so that you or your own reviewer can check it.
- A malicious browser extension or malware. Anything running in your browser can see what the browser sees, including a filled-in password. Install only extensions you trust.
Check it yourself
The security documentation goes into more detail, and the limits and roadmap page lists what is not covered.
Found a security problem? Please report it privately to support@grailvault.in.
Private by design, not by promise.
Start with a free trial and keep control of your data.