Privacy-first · Zero-knowledge · Offline-ready

Your Secrets.
Your Control.

CredStore is a military-grade encrypted digital vault for passwords, banking credentials, API keys, recovery codes, and every secret that matters — stored locally, owned entirely by you.

Free forever · No account required · Works offline

9:41 ●●●
🔒
🔑
GitHub
jeet@example.com
🏦
HDFC Bank
Banking
💳
Axis Credit Card
•••• •••• •••• 4521
⚙️
AWS Production
API Key
🔐
2FA Recovery Codes
Recovery Keys
+
🔒
Zero-Knowledge
We cannot read your data
📵
Offline First
Works without internet
XChaCha20-Poly1305
Military-grade encryption
🧬
Argon2id KDF
Best-in-class key derivation
🆓
Free Forever
No account required

Everything you need to
secure your digital life

Built for individuals who take their privacy seriously. No compromises.

🔐

Encrypted Local Storage

Every entry is individually encrypted with your master key using XChaCha20-Poly1305 AEAD. The SQLCipher database adds a second layer of encryption at rest — two independent keys, defense in depth.

SQLCipher XChaCha20-Poly1305 Argon2id
🤳

Biometric Unlock

Unlock instantly with Face ID, Touch ID, or Android biometrics. Your master key is wrapped in the Secure Enclave / Android Keystore — it never touches our servers.

🔢

PIN Unlock

Set a 6-digit PIN as a quick unlock alternative. The PIN derives a separate key via Argon2id to wrap your master encryption key — no shortcuts on security.

🎲

Password Generator

Generate cryptographically secure passwords with full control over length (8–64 chars), character sets, and entropy. Rejection sampling eliminates modulo bias.

📋

Secure Clipboard

Copied secrets auto-clear after 15, 30, or 60 seconds — configurable in Settings. Clipboard is only wiped if CredStore owns the current value; typing elsewhere is safe.

⏱️

Auto-Lock

Vault locks automatically when you leave the app. Configurable timeout from 30 seconds to 1 hour. Locking wipes the in-memory master key and clears the clipboard.

🔍

Instant Search

In-memory search index over title, username, URL, tags, and notes. Results appear before you finish typing — faster than any network request.

📦

Encrypted Backup

Export your entire vault as an encrypted backup bundle protected with a passphrase you choose. Import on any device. Your backup works even without a CredStore account.

🛡️

Device Security

Active monitoring for jailbroken / rooted devices and debugger attachment. A visible warning banner appears if your device's security integrity is compromised.

🌙

Dark Mode

Follows your system appearance. Full dark mode support built from the ground up — not an afterthought — with adaptive color tokens throughout every screen.

Accessibility

Every interactive element carries accessibility roles, labels, hints, and state — usable with VoiceOver on iOS and TalkBack on Android without any workarounds.

Premium
☁️

Cloud Sync Coming Soon

End-to-end encrypted synchronization across all your devices. The server stores only opaque encrypted blobs — zero-knowledge from end to end.

Engineered for
paranoid-level security

Every design decision is made with security as the primary constraint, not an afterthought.

Encryption Flow

🔑
Master Password
Never stored, never transmitted
🧬
Argon2id KDF
m=256 MiB · t=3 · p=4 (MODERATE profile)
🗝️
Master Encryption Key (MEK)
256-bit · Lives only in memory · Wiped on lock
XChaCha20-Poly1305 AEAD
192-bit nonce · Authentication tag · libsodium
🗄️
SQLCipher Database
Per-install DEK from OS Keychain / Secure Enclave
🏛️

Defense in Depth

Two independent encryption layers: your MEK encrypts each entry payload, and a separate device encryption key (DEK) encrypts the entire SQLCipher database file. Compromising one key is not enough.

👁️‍🗨️

Zero Knowledge

CredStore's backend never holds your master password, MEK, or any plaintext secret. Cloud sync stores only opaque encrypted blobs — we mathematically cannot read your data even if compelled.

⏸️

Memory Safety

The MEK lives in memory only while the vault is unlocked. On lock, it is explicitly zeroed from the buffer before garbage collection. Biometric and PIN paths wrap the key before writing it to the OS keychain.

📱

OS Secure Storage

Biometric-wrapped keys are stored in the iOS Secure Enclave (Hardware Security Module) or Android Keystore with BiometryCurrentSet access control — inaccessible without your registered biometric.

🎭

Screenshot Protection

Android sets FLAG_SECURE on the window so the vault never appears in screenshots or the recents screen. iOS overlays a blur effect on applicationWillResignActive.

🔬

No Modulo Bias

The password generator uses rejection sampling against libsodium's randombytes_buf — every character in the output has exactly equal probability regardless of the character set size.

Store anything that
matters to you

Type-specific forms with the right fields for every kind of credential — no generic catch-all boxes.

🔑

Login

Username · Password · URL

SitesAppsServices
🏦

Bank Account

Bank Name · Customer ID · Account Number

Masked by default
💳

Credit / Debit Card

Card Holder · Card Number · Expiry

Masked by defaultTap to reveal
⚙️

API Credential

API Key · Secret Key · Environment · Endpoint

DevelopersDevOps
🔐

Recovery Keys

Backup Codes · Recovery Phrases · Security Questions

2FASeed phrases
📋

Software License

Product Name · License Key · Purchase Date

SubscriptionsPerpetual
💻

Devices & WiFi

SSID · Password · SSH credentials

RoutersServers
📝

Secure Notes

Free-form encrypted content — any length, any structure

PrivateEncrypted

Custom Records

Not fitting a template? Use the custom type with user-defined fields — you define the structure, we encrypt it.

Start on mobile,
expand everywhere

Phase 1 is live on iOS and Android. Cross-platform sync, browser extensions, and web vault are in the roadmap.

Available Now
📱

iOS

  • Face ID & Touch ID unlock
  • Secure Enclave key storage
  • iOS Keychain integration
  • Blur on app switcher
Available Now
🤖

Android

  • Fingerprint & Face unlock
  • Android Keystore DEK
  • FLAG_SECURE screenshots
  • Root detection
Phase 3
🌐

Browser Extension

  • Chrome & Firefox & Edge
  • Safari extension
  • Autofill & save
  • OTP generation
Phase 4
💻

Web Vault

  • Access from any browser
  • Client-side decryption only
  • Device management
  • Account control

Simple, honest pricing.
No tricks.

CredStore is free today — unlimited entries, no account, forever. Premium (encrypted cloud sync, browser extension, web vault) is on the way.

Free
₹0/forever
Everything you need to secure your digital life, locally.
  • ✓ Unlimited vault entries
  • ✓ All credential types
  • ✓ Password generator
  • ✓ Biometric + PIN unlock
  • ✓ Encrypted backup & restore
  • ✓ Search & favorites
  • ✓ Auto-lock & clipboard clear
  • ✓ Dark mode
  • ✗ Cloud sync
  • ✗ Browser extension
  • ✗ Web vault
Download Free
Premium Monthly
₹99/month
Full premium features, billed monthly. Coming in a future update.
  • ✓ Everything in Free
  • ✓ Cloud sync
  • ✓ Unlimited devices
  • ✓ Browser extension
  • ✓ Web vault
  • ✓ Device management
  • ✓ Password health audit
  • ✓ Breach monitoring
  • ✓ Priority support
Coming soon

Today CredStore is 100% free with no in-app purchases. Premium plans above are planned for a future release — pricing may change at launch.

Common questions

No. CredStore uses a zero-knowledge architecture. Your master password is never stored or transmitted anywhere. All encryption and decryption happens on your device. Even if CredStore's servers were seized, there is nothing they could decrypt — they only hold opaque blobs of ciphertext (and only for Premium sync users).

Nobody can recover your vault without the master password — including us. This is a fundamental property of zero-knowledge design. We strongly recommend setting up an encrypted backup export stored in a safe location before this situation arises. The backup is encrypted with a separate passphrase you choose.

Yes, completely. The free plan is entirely local and never requires an internet connection. It works offline permanently. Premium sync is optional and only activates when you explicitly enable it.

CredStore uses XChaCha20-Poly1305 for authenticated encryption via libsodium. This cipher is constant-time on all platforms, uses a 192-bit nonce (vs 96-bit for AES-GCM), and does not require hardware AES acceleration — critical for lower-end Android devices. The security margin is equivalent to or greater than AES-256-GCM. Key derivation uses Argon2id, the winner of the Password Hashing Competition.

CredStore never accesses your fingerprint data. When you enroll biometrics, your master encryption key is wrapped and stored in the iOS Secure Enclave or Android Keystore with BiometryCurrentSet access control. The OS handles biometric verification entirely — CredStore only receives the unwrapped key on success.

Not yet. Family Vault (Phase 6) and Business Edition (Phase 9) are on the roadmap. Business features include shared vaults, teams, role-based access, and audit logs. Sign up to be notified when they launch.

CredStore is completely free today, with no in-app purchases — the entire local vault is yours at no cost, forever. Premium (encrypted cloud sync, browser extension, web vault) is planned for a future release. When it launches it will be available via Apple In-App Purchase, Google Play Billing, Stripe, and Razorpay, with one subscription covering all your devices.

Built in public,
shipped with intention

Phase 1
Android + iOS MVP
Core vault, encryption, biometrics, backup, search, auto-lock.
Phase 2
Premium Cloud Sync
Zero-knowledge encrypted sync across unlimited devices.
Phase 3
Browser Extension
Chrome, Firefox, Edge, Safari — autofill, save, generate, OTP.
Phase 4
Web Vault
Full vault access from any browser with client-side decryption.
Phase 5
Password Health Audit
Weak, reused, and old password detection. Breach monitoring.
Phase 6
Family Vault
Shared vaults for families with emergency access.
Phase 7
Secure Sharing
Send credentials securely with one-time links.
Phase 8–9
Developer & Business
Teams, RBAC, audit logs, SSH keys, certificates, infra secrets.

Start protecting your
digital life.

Free, no account, no cloud — just encryption. Launching soon on iOS & Android.

iOS — Coming soon Android — Coming soon
🔒 Your data never leaves your device