Your vault,
your server.
Vaultiq is a zero-knowledge password manager you host yourself. Items are encrypted on your device before they sync, so your server cannot read their contents.
- Firefox & Chrome extension
- Android
- Self-hosted server
The short version.
Encrypted on your device
Items are sealed before they are saved or synced. Your master password and vault key never leave the device.
Your server cannot read items
The server stores and relays encrypted items. It holds no decryption keys, though item counts, sizes and timing remain visible.
No recovery backdoor
We can't reset your password because we can't read your vault. Lose the master password and the vault stays locked.
Encrypted before it leaves.
Unreadable where it lands.
Three of the four steps happen on your device. The server only takes part in the last one.
fig. 2 — the server is a box of sealed blocks. It keeps them; it can't open them.
-
01
Master password
You type it on your device. It is never sent to the server or stored anywhere.
-
02
Key derivation
Argon2id turns it into a key, slowly and memory-hard. HKDF splits that into separate keys per purpose.
-
03
Items are encrypted
Each item is sealed with XChaCha20-Poly1305. Tampered data fails to decrypt and is rejected.
-
04
Encrypted items sync
Your server stores and relays the sealed blocks. In local-only mode, nothing syncs at all.
What it looks like.
Illustrations, not screenshots. Every name and credential shown is made up.
Autofill in the browser
The popup opens on the login that matches the site you're on. One button fills it. The whole vault is searchable from the same place.
Illustration — not a screenshot
Vault and search
Logins up front with search. Cards, identities and notes are one tap away.
Illustration — not a screenshot
Autofill in other apps
A sheet slides over another app's login form. Fill a match, search the vault, or save a new login.
Illustration — not a screenshot
Authenticator codes
TOTP codes live beside the logins they protect, with a countdown to the next one.
Illustration — not a screenshot
Self-host it, or skip the server.
Your own sync server
Run it on hardware you control. It stores sealed blocks and passes them between your devices.
- Docker + Caddy
- Invite-only sign-up
- Multiple users
- Admin CLI
- Audit log
$ git clone https://github.com/rustiqz/Vaultiq.git $ cd Vaultiq && cp .env.example .env $ docker compose up -d
Full walkthrough: server guide
No server at all
Keep the vault on one device. Nothing syncs and nothing listens on a port. Encrypted backups cover you if the device is lost.
- No account anywhere
- No network sync
- Encrypted backup
- Same crypto core
From nothing to synced.
- 01
Start the server
Set POSTGRES_PASSWORD and VAULTIQ_DOMAIN in .env, then docker compose up -d. Caddy gets its own certificate; the domain must already point at the machine.
- 02
Get an invitation
Sign-up is invite-only. On a fresh server a first registration token is written to the server log; after that, mint more with the admin CLI.
- 03
Create your vault
Install the extension or the Android app, choose a long master password, and register with the token. The password never leaves the device.
- 04
Add a device
Use Add a device to show a QR code, scan it on the second device, and enter the master password there. A token alone is not enough.
There are no store listings yet, so both apps are built from source. You need Rust, Node 24 and pnpm; the Android build also needs the Android SDK and NDK.
Browser extension
$ cd extension $ pnpm install $ pnpm run build
Firefox: open about:debugging, choose This Firefox → Load Temporary Add-on, and pick dist/manifest.json. Temporary add-ons are removed when Firefox restarts.
Chrome: open chrome://extensions, turn on Developer mode, choose Load unpacked, and pick the dist folder.
Android app
$ cd mobile $ pnpm install $ pnpm run crypto $ cd android && ./gradlew assembleDebug
Install the debug APK from app/build/outputs/apk/debug/. Android autofill is switched on in system settings under the autofill service.
Prefer no server? Choose “Use without a server” when creating the vault. Step-by-step: extension · Android · all the docs.
The everyday parts.
Security, honestly.
What Vaultiq protects you from, and what it can't. If something in the second column rules it out for you, better to know now.
Defends against
- A compromised server
Full control of the server gets an attacker sealed blocks. There are no keys there to take.
- A stolen database
A dump contains ciphertext and metadata. The wrapped vault key permits offline password guesses at Argon2id cost.
- Tampered ciphertext
Every item is authenticated. Modified data fails to decrypt and is rejected, not silently used.
- Network eavesdropping
Sync sends encrypted items over HTTPS. Traffic volume and timing can still be observed.
Does not defend against
- A compromised device
If malware controls your device while the vault is unlocked, it can read what you can read.
- A keylogger
Anything recording your keystrokes can capture the master password as you type it.
- A weak master password
Argon2id slows guessing down. It can't make a short or reused password strong. Use a long passphrase.
- Key derivation
- Argon2id
- Core
- Rust, shared across platforms
- Encryption
- XChaCha20-Poly1305
- Network in core
- zero calls
- Key separation
- HKDF, domain-separated
- Tests
- known-answer tests
No independent audit yet. Known-answer tests pin what the crypto core produces, and the code is open to read.
Audit it yourself.
The Rust crypto core, the server and both apps live in one repository, with known-answer tests for the cryptography. It is free software under the AGPL-3.0.
github.com/rustiqz/VaultiqLicensed under the GNU AGPL-3.0. If you run a modified version as a network service, you must offer its source to its users.
Issues and pull requests are welcome; read CONTRIBUTING.md first, since some changes need discussion. Found a vulnerability? Follow SECURITY.md rather than opening a public issue.
Not yet.
- iOS app
- Sharing between users
- Passkeys
- Account recovery
Today: Firefox, Chrome, Android, a self-hosted server, and local-only mode.
Straight answers.
What if I forget my master password?
The vault stays locked. Nothing can reset it, because nobody can read the vault, you included. Encrypted backups do not help: they still need the master password.
Can the server operator read my passwords?
No. The server holds sealed items and a wrapped key, never the keys to open them. It can still see how many items you have, their sizes, and when you sync.
Does it phone home?
No telemetry, analytics or update checks. The crypto core makes no network calls at all, and the apps talk only to the server you point them at, if any.
How is this different from Bitwarden or 1Password?
It is small and self-hosted only: one person, one Rust core, no hosted service. Established products have audits, more platforms and sharing. If you need those, use them.
Is it free?
Yes. It is licensed under the AGPL-3.0. There is no hosted service and nothing to pay for; you run the server yourself.
Can several people share one server?
Yes, by invitation. Each person has a separate vault the others cannot read. Sharing items between people is not built.
Can I move from local-only to a server later?
In the browser extension, yes: connect a local vault to a new server and it uploads. On Android there is no conversion yet.
What can I import?
CSV, Bitwarden JSON and Proton Pass JSON. Logins and secure notes come across from all three; Bitwarden cards and identities do too. Delete the export file afterwards, since it is plain text.
Is there an iOS app?
No. Today it is Firefox, Chrome and Android.
How do I report a vulnerability?
Follow SECURITY.md and do not open a public issue.