Keyvalv
Coming soon Get notified

A password vault in your cloud, not ours.

Thanks. We will email you when Keyvalv is ready.

That did not go through. Check the address and try again.

Keyvalv keeps your passwords in one encrypted file, in your own Google Drive, iCloud Drive or any folder you sync. We run no servers, so there is nothing of yours for anyone to breach. First release: Chrome and Edge.

A small safe with its round door swung open, standing on a plinth labelled "your cloud drive". Through the doorway, four signed records are stacked on top of each other, each sealed to the one below. Beside the plinth, an empty dashed footprint is labelled "Keyvalv servers: none". Pull any record out and every seal above it breaks.

What if someone changes your vault behind your back?

Your vault is a file in cloud storage. If that storage is hacked, glitches, or hands back an old copy, most password managers would open it without question. Keyvalv checks first.

  1. Every change gets a fingerprint

    A short code worked out from the change itself. Different content always gives a different code, so a fingerprint cannot be reused for something else.

  2. Each fingerprint includes the one before it

    That links the records together, like pages that each quote the page before. Your devices sign every link.

  3. Change the past and the links break

    Edit one old record and its fingerprint no longer matches. Every record after it was built on the old fingerprint, so those fail too. Keyvalv refuses that copy, keeps your last good one and tells you.

Try it. You are the attacker.

This is a small vault history. Your browser is working out the real fingerprints right now. Pick any record and change it in secret.

    Checking the history.

    Why Keyvalv

    No servers to breach

    Your vault is a file in storage you already own. It never passes through us, so a break-in at Keyvalv could not expose it.

    History you can verify

    Every device signs its changes and links them to the ones before. An edited or rolled-back vault is caught and refused, not quietly trusted.

    Yours to take elsewhere

    The vault uses the open KeePass format. It opens in existing apps on your phone, and it leaves with you whenever you like.