Browser autofill
Use credentials from your encrypted vault through the Chromium Extension.
A local-first password manager.
Browser autofill. Peer-to-peer synchronization.
Your passwords, within reach.
Use it on your own, self-host the sync infrastructure, or choose Online Services for managed P2P infrastructure and encrypted backups.
Start with the passwords you already have. Use them in your browser. Take them with you whenever you leave.
Import your credentials, then find everything in one local vault.
Use credentials from your encrypted vault through the Chromium Extension.
Import from Bitwarden, 1Password, KeePass, LastPass, Chrome and Firefox.
Export your data and create manual encrypted backups at any time.
Each device holds its own encrypted vault. When you sync, your devices connect directly where possible. A TURN relay carries encrypted traffic when they can’t.
Signaling helps your devices find each other.
Both vaults must be open and unlocked.
New links sync automatically when connected.
The password manager is free forever. A subscription pays for managed infrastructure and encrypted backup storage.
THE PASSWORD MANAGER
A complete password manager, on your own terms.
Open Cryptex VaultOPTIONAL MANAGED SERVICES
Your vault stays yours. We run the supporting infrastructure.
Continue with monthly planNew to Online Services? Start with monthly billing before committing to a year.Both devices must be online. You initiate synchronization. Backups are stored separately as encrypted copies.
Local ownership matters most when something goes wrong. Keep a backup and preserve your recovery information.
Your other devices keep their complete vault. Revoke the lost device’s Online Services permissions. Its local encrypted vault is not remotely erased.
Restore a manual encrypted backup, or retrieve your managed backup through Online Services. You still need the required recovery information.
Keep using your local vault, export your data and restore manual backups. The public source code lets you build the software and run your own sync infrastructure. Keep a manual backup independent of Online Services.
Online Services Recovery Kit
Use its User ID and phrase to find available managed backups.
Vault recovery code
Restore access to the vault itself.
OPEN SOURCE - AGPL-3.0
Read how the vault works, where its protection ends, and what the infrastructure can observe. Inspect the source code and follow the development on GitHub.
Explore securityCryptex Vault has not yet undergone an independent third-party security audit. Internal red-team testing has been performed; independent review is on the roadmap.
AVAILABLE NOW
Web app, Chromium Extension, autofill, imports and exports, P2P sync, manual backups and optional managed services.
IN DEVELOPMENT
An Android app and credential sharing via a URL are in development. Links will let you share with people who do not use Cryptex Vault.
PLANNED
Advanced Security Report, custom backup destinations, Firefox and iOS support, and granular device-linking permissions. Priorities and version targets may change.
Your encrypted vault lives locally on your devices. If you choose managed backups, Online Services also store an encrypted copy. Vault contents and passwords are not sent to the infrastructure in plaintext.
Synchronization happens between your devices, without a central vault serving changes while a device is offline. Both vaults must be open, unlocked, and reachable. New links connect and sync automatically by default; you can change those settings or sync manually.
Your other devices retain their complete vault. Revoke a lost device’s Online Services permissions promptly; this does not erase its local vault. If every device is lost, you need a manual or managed backup and the required recovery information. Your Online Services Recovery Kit contains the User ID and phrase needed to find available managed backups from your root devices. Your vault password or vault recovery code unlocks the restored vault.
Not yet. Internal red-team testing has been performed. Independent review is part of the security roadmap; it is not a completed audit.
No account is required for local use. Online Services require a subscription and a separate setup in the app.
A TURN relay can carry the encrypted traffic between your devices. Synchronization remains end-to-end encrypted; Cryptex Industries d.o.o. cannot read the relayed vault contents.
If you still have access to your vault, secure a backup and your recovery information now. If you lose access, every device, and the required recovery information, Cryptex Industries d.o.o. cannot guarantee recovery or decrypt your vault for you.
Your locally stored vault remains yours. You can export your data and restore manual backups. The source code is public, so you can build the software and run your own sync infrastructure. Managed services depend on Cryptex Industries d.o.o. remaining operational, so keep a separate manual backup.
Cryptex Vault keeps a complete encrypted vault on each device and adds browser autofill and direct device-to-device synchronization. KeePass is commonly file-based, while Bitwarden and Vaultwarden synchronize through a central server. Cryptex Vault synchronizes peer to peer instead, so both devices must be online at the same time. You can self-host the connection infrastructure or use optional managed services. The tradeoff is direct ownership and control instead of always-on server synchronization.
Managed backups store encrypted vault copies. Signaling and relay infrastructure process connection metadata, which can include IP addresses, timing and WebRTC connection information. Subscription and payment data are separate from vault contents; see the Privacy Policy for their handling.
Create a vault. Import your passwords.
No account required for local use.