Password manager · Zero-knowledge

One password. Everything else, protected.

Valtira encrypts your passwords, notes and 2FA codes on your device — before anything is saved or synced. The key stays with you. Not with us.

Free during early access · No account needed to start

The Valtira vault showing a list of logins and the details of a selected login
  • Encrypted on your device
  • AES-256-GCM · Argon2id
  • No ads, no trackers
  • Open, documented architecture

Zero-knowledge architecture

Your vault is locked before it ever leaves your hands.

Valtira never needs your master password on a server. It turns it into keys on your device, and only encrypted data is ever stored or synced.

  1. Your master password

    Typed on your device. Never stored, never sent.

  2. Key derivation

    Argon2id with 64 MiB of memory makes every guess expensive.

  3. Your vault key

    A random 256-bit key, unlocked only with your master password or recovery key.

  4. Encrypted vault

    Every item is sealed with AES-256-GCM and bound to its identity.

  5. Only your devices decrypt it

    Our servers store ciphertext they cannot read.

What our servers see
AQHx9…c7Qe AQF2m…9kLr AQG8s…Tz3w

Encrypted blobs, item counts and timestamps — never names, URLs, usernames or passwords.

Read the full security architecture

Built for everyday calm

Everything in one place. Nothing in plain sight.

A vault that feels effortless

Logins, secure notes, cards, identities, Wi-Fi, API keys, licenses and recovery codes — organized with favorites, tags and categories, and found instantly with local search.

  • Search runs on your device — never on a server
  • Passwords hidden by default, copied with one click
  • Clipboard cleared automatically (after 30 seconds by default)
A vault that feels effortless

Strong passwords, generated the right way

Passwords and passphrases from your browser’s cryptographic random generator — with the options you actually need, and nothing stored.

Try the generator

This runs entirely in your browser. Nothing is sent or saved.

••••••••••••••••••••

A Security Center that respects your privacy

Find reused, weak, old or insecure logins. The analysis runs locally. An optional breach check sends only a 5-character hash prefix — never your password.

A Security Center that respects your privacy

Unlock with a touch — when your device can do it safely

Valtira uses passkeys with the WebAuthn PRF extension for Windows Hello, Touch ID, Face ID and Android biometrics. If your browser or device can’t do it securely, we don’t fake it: your master password is the fallback.

Your vault on every device

Encrypted sync keeps your devices up to date. Conflicts never overwrite silently — both versions are kept. Remove a lost device and it can no longer sync.

Two-factor codes, right next to your logins

Store TOTP secrets inside the encrypted item and get live 6-digit codes. Convenient — and we explain the trade-off honestly.

Devices

Start on the web. More devices are on the way.

We only call something available when it works. Here is where Valtira runs today.

  • Web app

    Available

    Current Chrome, Edge, Firefox and Safari on desktop and mobile. Installable and usable offline.

  • Browser extension

    Coming soon

    Find and fill logins on the current site — only when you click, never automatically.

  • Android

    Coming soon

    Native app with fingerprint unlock and protected screens.

  • iOS

    Coming soon

    Native app with Face ID and Keychain protection.

Privacy by design

Your data is not our business model.

No ads. No tracking.
No advertising, no analytics scripts, no third-party trackers — not on this page and not in the app.
We cannot read your vault
Names, URLs, usernames, notes, tags and passwords are encrypted before they leave your device.
Minimal metadata
For sync we need your email address, encrypted items and timestamps. We don’t keep IP addresses in our database — rate limiting uses short-lived keyed hashes.
Your data stays portable
Export an encrypted backup anytime, or a plain CSV/JSON after an explicit warning.

Questions, answered honestly

Can Kunz Systems see my passwords?

No. Your vault is encrypted on your device with a key derived from your master password, which we never receive. Our servers only store encrypted data they cannot decrypt. As with every web app, you trust the code your browser loads — which is why we document the architecture openly and load no third-party scripts.

What happens if I forget my master password?

You can open your vault with the recovery key you saved during setup and choose a new master password. If both the master password and the recovery key are lost, nobody — including Kunz Systems — can decrypt the vault. That is the price of real zero-knowledge protection, so please keep your recovery key safe.

Does Valtira work offline?

Yes. After setup your encrypted vault lives on your device and the app is cached, so you can open and edit it without an internet connection. With sync enabled, changes are uploaded when you are back online.

How does biometric unlock work?

Valtira creates a passkey on your device and uses the WebAuthn PRF extension: after you verify with your fingerprint, face or device PIN, the authenticator releases a secret that unlocks a copy of your vault key. Nothing biometric ever reaches Valtira. If your device or browser doesn’t support this securely, the option is not offered. Every 14 days you confirm your master password so you don’t forget it.

Where is my data stored?

In your browser’s storage on your device, always encrypted. If you turn on sync, encrypted copies are stored on our sync servers so your other devices can download them. Nothing readable is stored anywhere.

Can I export my data?

Yes. You can create an encrypted backup file at any time and restore it without an account. You can also export CSV or JSON in plain text after confirming your master password and a clear warning.

Can I import from my browser or another password manager?

Yes. Valtira imports CSV exports from Chrome, Edge, Firefox and Safari, and exports from Bitwarden, 1Password and LastPass. Files are processed locally and never uploaded.

Is Valtira audited?

Not yet. Valtira uses established, audited cryptographic building blocks (WebCrypto, libsodium) and a documented design, and an independent audit is planned before we leave early access. We will publish the results.

Take back control of your passwords.

Create your encrypted vault in a minute. No account required to start.

Create your vault