DotVault
Features Security Pricing Blog Download
Security

How DotVault protects your secrets

Last updated: October 4, 2026

DotVault is a desktop app that keeps API keys, SSH keys, tokens, web logins and environment variables in an encrypted vault on your own computer. This page explains how that protection works, what it does not cover, and what the optional sync stores. If something here is unclear or you think it is wrong, tell us at support@dotvault.app.

Encryption

  • Cipher: each project is serialised, then encrypted with AES-256-GCM using a fresh random 12-byte nonce, and stored in a local SQLite file.
  • Key: a 32-byte key is derived from your master password and a random 16-byte salt with Argon2id. The key is held in memory only while the vault is unlocked, and it is wiped when the vault locks.
  • What is stored in plain text: only each project’s internal id and its created and updated times, which are used for ordering. Names, descriptions and every credential are inside the encrypted data.

Where plain text exists

Your secrets are decrypted only inside the app’s Rust backend, for as long as you are viewing or editing them. The window you interact with is a separate web view with a strict content security policy and no network access of its own. The vault locks itself after a period of inactivity that you choose, and values you copy are cleared from the clipboard afterwards.

Backups

An exported backup is encrypted with a separate key derived from a passphrase you choose, so the backup file is unreadable without that passphrase. Changing your master password does not change old backups: they still open with the password or passphrase they were made with.

Tamper warning

DotVault keeps a record of the vault’s revision in your operating system’s keychain. If an older copy of the vault file is put back, the revisions no longer match and the app warns you instead of opening it silently. This depends on the keychain being available. Windows, macOS and most Linux desktops provide one.

Changing your master password

A change re-encrypts every project with a new key and a new salt in one step, and scrubs data protected by the old password from the vault file. If sync is on, the account password changes at the same time and every other device and browser connected to the account is signed out.

Optional sync

Sync is off by default. Until you turn it on, the desktop app makes no network connections and sends no telemetry. When it is on:

  • Your projects are encrypted on your computer first. Only the encrypted data leaves it, over HTTPS.
  • Your master password and encryption key never leave your computer. To recognise you at sign-in, the server stores a hash of a proof derived from your key. It cannot decrypt your vault with it.
  • The server stores your email address, your encrypted projects with their ids, sizes, timestamps and revision numbers, your device names, and hashes of device sign-in tokens. The privacy policy lists everything.
  • The web app does its encryption and decryption in your browser, with the same design.

One consequence matters: because the sign-in proof is derived from your master password, a stolen copy of our database could be attacked offline by guessing passwords. Argon2id makes every guess expensive, but a strong, unique master password is what keeps your vault safe in that case.

What DotVault does not protect against

  • Malware, a keylogger or a screen recorder running on your computer, especially while the vault is unlocked.
  • Someone using your computer while it is unlocked.
  • A weak or reused master password. Encryption cannot make a guessable password strong.
  • Other programs reading the clipboard during the short time a copied value is on it.

Limits you should know about

  • No recovery. If you forget your master password, nobody can open your vault, including us. There is no reset and no backdoor.
  • No independent audit yet. DotVault has had internal reviews and automated testing, but it has not yet had an independent external security audit.
  • Installers are not code-signed yet, so Windows and macOS may show a warning the first time you open the app.

Reporting a vulnerability

Please do not open a public issue. Email support@dotvault.app with the affected version and platform, the exact steps to reproduce, what you expected and what happened, and whether any secret material could have been exposed. We aim to acknowledge reports within 72 hours and to publish a fix before any public disclosure.

DotVault

The encrypted vault for developer secrets: API keys, SSH keys, tokens, logins and environment variables, organised by project on your own computer.

Product

Features Security Pricing Blog

Get started

Download

Legal

Terms of Service Privacy Policy Cookie Policy

© 2026 Dotvault