Per-Device Encryption
In Vauz, each password gets its own unique encryption key, layered on top of device-specific encryption — your device is the root of trust
In Vauz, each password gets its own unique encryption key, layered on top of device-specific encryption — your device is the root of trust
Your data stays on your device. No server outages, no internet dependency, no subscription lock-in. Access your passwords anytime, in any location
Two layers, both industry standard: AES-256-GCM over the whole vault, and a separate key per record derived with HKDF-SHA256
Your passwords do not leave your device. No cloud, no sync, nothing to breach at our end — backup and sharing are coming, and will be opt-in
Encryption keys come from the device, not from something you need to remember. The optional V-Key locks the UI from prying eyes only. Your vault is always encrypted
HKDF-SHA256 for per-record keys, scrypt at N=131072 for encrypted exports. Published parameters, no homegrown cryptography
Before filling a login, the browser extension checks the address you are really on. An address disguised as a well-known site gets no autofill; a near-miss gets a warning first. Checked inside the extension; nothing leaves your device
With Vauz, you can securely generate, store, and access your passwords with ease. We've designed the app with a clean and responsive interface, ensuring a seamless experience across all your devices. Your data is encrypted, giving you peace of mind knowing your sensitive information is always protected!
Absolutely! Vauz is designed to function seamlessly offline, ensuring your data security even
without an internet connection.
Vauz offers a free plan that provides essential password management features at no cost.
While the free plan is perfect for basic needs, you can also upgrade to our
Plus or Premium plans to unlock additional features.
The Plus plan is available for CAD 4.70 per month, and the Premium plan is available for CAD 7.60 per month
While Vauz is primarily designed for storing passwords, you can also store secure notes or other sensitive information
No. Vauz does not require a master password from you. Vauz's V-Key is optional, and it is a lock on the app rather than the key to your data. In a traditional password manager the master password derives the encryption key, so forgetting it costs you every password. In Vauz the keys come from the device, and each record gets its own key derived with HKDF-SHA256. Setting a V-Key adds a second check before the app will open, it does not change how anything is encrypted.
Two things follow. There is no password to lose. And because the root is the device rather than something you typed, the vault file on its own does not open on other hardware. The trade is that the device becomes what has to be protected — see our threat model for what that does and does not cover
You can easily cancel your subscription through Vauz portal. Alternatively, you may terminate it at any time upon written notice via email. Upon termination, you must cease all use of the Software and destroy all copies in your possession as per the terms of the agreement
No. Your vault is stored only on your own device and never reaches our servers. There is no setting that changes this today, because there is nothing to switch on: encrypted cloud backup, cross-device sync and password sharing are planned, not shipped. When they arrive they will be opt-in, and we will say so here rather than quietly enabling them
What Vauz denies is portability of the file. The vault is encrypted with AES-256-GCM under a key bound to the computer that created it, so the file on its own does not open on other hardware, and time spent with it elsewhere does not change that.
That binding is not a substitute for your operating system's disk encryption — turn on BitLocker, FileVault or LUKS. It denies the file, not the machine: someone who images your whole drive has taken more than the file.
On the original machine it is a different question, and we would rather be straight about it: anything already running as you on your own computer is inside the boundary. A V-Key raises the bar there, but does not remove it. Section 4 of the threat model sets out exactly which attackers this design stops and which it does not
Yes. Your browser keeps passwords in its profile, readable by anything running in the browser, and syncs them to the vendor — one bad extension reaches all of them. A cloud manager holds your vault on its servers. Should a breach happen, and attackers guess master passwords offline, with no rate limit. We hold no vaults.
And a master-password vault is portable. A Vauz vault is bound to the computer that created it, and the file on its own does not open on other hardware.
That binding is not a substitute for your operating system's disk encryption. An attacker who takes a full image of your drive, or who can run code on your machine, is covered by section 4 of our threat model rather than by this
Contact Us