VaultKeepR
Decentralized. Private. Yours.
Master password + wallet signature. Vault Sync to IPFS, optional signed delegation, fragmented recovery (Premium), TOTP and email aliases. Extension, iOS, web—you keep the keys.
Web3 · Privacy-first
Your keys. Your data. Your sovereignty.
Password manager, autofill, and sync without a central password database.
Decentralized
Encrypted vault on IPFS. No central server holds your secrets. You control the CID and the keys.
End-to-end encrypted
Argon2id + XChaCha20 + EIP-191 wallet signature. Optional unlock delegation so you are not prompted for every sync.
Privacy by default
No account, no tracking. Zero-knowledge: we never see your vault contents.
Trusted Security
Built for the security-conscious
Enterprise-grade encryption meets Web3 simplicity. Your credentials, your keys, your rules.
Powered by battle-tested technologies
What early adopters say
Privacy is not an option. It's the default.
VaultKeepR does not collect analytics, telemetry, or user data. Period.
Zero tracking
No Google Analytics, no cookies, no fingerprinting. We don't know who you are and we never will.
No central server
Your encrypted vault lives on IPFS. We don't host databases of your passwords — there's nothing to breach.
End-to-end encrypted
Argon2id + XChaCha20 + wallet signature. Your master password never leaves your device.
How it works
From wallet connect to automatic backup—in a few steps.
Connect wallet
Use WalletConnect with your preferred EVM wallet. Your address identifies the vault.
Lock & Encrypt
Create a master password. Combined with your wallet signature, it derives a unique encryption key via Argon2id.
IPFS & Vault Sync
Save your encrypted vault to IPFS. Enable Vault Sync with a time-limited signed delegation for seamless sync.
Everywhere
Web app, Chrome extension (autofill), iOS with Face ID and system AutoFill. Same vault, custom folders and identities.
Built for real use
Sync, recover, and protect credentials across devices—without trusting us with your passwords.
Zero-knowledge
Decryption only on your device. We never see plaintext passwords, cards, or notes.
No account
No email signup. Wallet + master password. Fewer breach surfaces.
Pseudonymous by design
Use a dedicated wallet if you want separation from real-world identity.
IPFS backup
Encrypted blob on IPFS. You can clear CID cache and re-fetch; nothing stored as clear text on our side.
Password + signature
EIP-191 signing plus Argon2id. Unlock delegation reduces how often you must sign for Vault Sync.
Modern crypto
Argon2id key derivation and XChaCha20-Poly1305. Strong defaults for vault encryption.
Extension, iOS, web
Autofill in the browser, AutoFill on iOS, full vault UI on the web—including groups, identities, and TOTP (Premium).
Import & export
Bitwarden, CSV, JSON, PGP. Export plain, encrypted, or PGP-wrapped for your own backups.
Minimal telemetry
No ads, no behavioral profiling. Premium and alias use standard payment and email flows only where you opt in.
Vault Sync
After unlock, optionally delegate signing so changes sync to IPFS automatically within a window you choose in Settings.
Fragmented vault (Premium)
Split the vault into five shares (3-of-5 Shamir). Recovery ID is independent of your wallet for disaster recovery.
Email aliases (Premium)
Create forwarding addresses on your domain to hide your real inbox from signups and leaks.
Tech stack
Stack you can reason about: distributed storage, modern KDF, wallet auth.
IPFS
Content-addressed, distributed storage for encrypted vault blobs
Open source
Core and clients auditable by the community
WalletConnect
Standard wallet signing (EIP-191), no custodian
Argon2id
Memory-hard key derivation