Security
In plain words: what Keyvalv protects you from, what it cannot protect you from, and how to tell us about a problem.
What Keyvalv protects against
- A break-in at Keyvalv. We run no servers and hold no vaults, so there is nothing of yours to take from us.
- A break-in at your cloud storage. Your vault is encrypted on your device before it is uploaded. Someone who gets into your Google Drive or iCloud gets a file they cannot read without your master password.
- A vault that was changed behind your back. Every change your devices make is stamped and signed. If your storage is hacked, glitches, or hands back an old copy, Keyvalv refuses it, keeps your last good copy and tells you.
- A lost or stolen phone or laptop. The vault stays locked behind your master password.
What it does not protect against
- A device that is already compromised. Malware that can read your screen or your keyboard can read your passwords too, whatever manager you use.
- A weak master password. Everything rests on it. Keyvalv helps you pick a strong one and will never store or reset it.
- Someone who has both your file and your master password. Keep the printed emergency sheet somewhere safe.
Report a vulnerability
Write to security@keyvalv.com. We aim to reply within a few working days, fix confirmed issues as a priority, and credit you if you wish. Please give us reasonable time to fix a problem before publishing it. Details are also in /.well-known/security.txt.
Before launch
We intend to publish a plain-language and a technical write-up of the design, including the file format, how the master password becomes a key, and how changes are stamped and signed, before Keyvalv launches, so anyone can check our claims. Keyvalv has not yet been independently audited; we will say so here when it has.
Back to keyvalv.com