Axovault
Zero-Knowledge Encryption

Your secrets,
sealed by math.

A credential vault encrypted on your device with AES-256-GCM. We host the ciphertext — only you hold the key.

Vault unlockedAES-256-GCM
GitHub
alex@axovault.dev
AWS Production
AKIA••••••••
Recovery Phrase
12 words • cold wallet
Architecture

Built so we can't betray you.

Even with full database access, your secrets remain mathematical noise.

AES-256-GCM

Authenticated symmetric encryption. Every secret tamper-evident, even from us.

Argon2id KDF

Memory-hard key derivation. Your master password is never transmitted.

Zero-Knowledge

Server only ever stores ciphertext. Decryption happens exclusively on your device.

Flow

Three steps. No magic.

  1. 01

    Set master password

    Argon2id derives a 256-bit key. Your password never leaves the device.

  2. 02

    Encrypt locally

    Each secret gets a unique IV and is sealed with AES-256-GCM in your browser.

  3. 03

    Sync ciphertext

    Only the encrypted blob travels to our servers. Even we see nothing.

Auto-clearing clipboard

Copied secrets vanish from your clipboard after 12 seconds.

Strong password generator

Cryptographic randomness, configurable charset, instantly stored.

Auto-lock

Vault re-locks after inactivity. No persistent plaintext, ever.

Cross-device sync

Encrypted blob syncs everywhere. Decrypt only on trusted devices.

Take back your keys.

Free during beta. End-to-end encrypted from day one.

Create your vault