A private map for every secret
Your vault stays yours
Store, find, and share secrets with encryption that begins and ends on approved devices.
Two keys, one private boundary
Signing in proves who you are. Unlocking the vault proves you hold the secret that can decrypt it.
Account key
Opens your ExcelPass account and identifies your session.
Vault key
Comes from your master password and unlocks data locally.
Server boundary
Receives ciphertext, never the vault key needed to read it.
Encryption follows every secret
Readable data exists where it is useful. Everywhere else, it remains encrypted.
On your device
Plaintext stays local
A secret is readable only inside your browser while you work with it.
In transit and storage
Ciphertext crosses the boundary
Encryption happens before transit, so Supabase stores ciphertext instead of readable vault data.
On approved devices
Decryption returns to the edge
You and approved group recipients decrypt locally after access is verified.
Find what you need without slowing down
Your personal vault keeps everyday credentials close, searchable, and ready to copy when the login screen appears.
- Daily retrieval
- Search by service or account, reveal only when needed, then copy without reorganizing your vault.
- Secret health
- Spot weak or reused passwords in the same place you maintain the credentials that need attention.
- Ownership
- The group owner decides what belongs in the shared vault.
- Access
- Only approved members receive the encrypted material needed to open it.
- Expiry
- Time limits make temporary access explicit before anyone accepts it.
- Revocation
- Remove a member to stop future access without sending a new plaintext copy.
Share access without giving up ownership
Group vaults make the relationship visible before a secret is shared, while decryption stays with approved recipients.
Start with a vault only you can unlock
Create your account, set a separate master password, and encrypt your first secret locally.
Create account