skip to content
kaizenvault
the ideahow it workslimitsget notified

sealed on-device · android

a password manager
we can’t read.

your pin becomes a key on your phone, and that key never leaves it. everything you save is sealed before it syncs. you sign in with an account, but it can’t open your vault, and neither can we. breach us and all you get is noise.

get notified→see the proof
  • keys on device
  • hardware-backed
  • sealed sync
  • zero telemetry
vault / trust modelno server key
on your phoneon our serverpasswordderiveyour keynever leaves the phoneencryptsealedsyncour server✗ no key, can’t open

who holds what

you hold the keys.
we hold nothing we can read.

everything that can open your vault stays on your phone. everything that reaches us is sealed or public by design. here is the split, line by line.

on your phoneyours
  • ●your master pin, known only to you
  • ●the keys it derives, made on-device
  • ●your logins and 2fa codes in the clear, only while open
  • ●every decryption, start to finish
on our serverson record
  • ○sealed blobs we have no key for
  • ○your email, to send sign-in codes
  • ○a hash of your account password
  • ○your public keys, so people can share to you
  • ○random salts and version counters
  • ○and nothing, anywhere, that opens your vault

breach us, subpoena us, or turn a rogue admin loose. the answer never changes: we have nothing to give.

what we promise

four lines we will not cross.

01

we can never read a single item in your vault. not during a breach, not under a subpoena, not on our worst day.

02

your keys are born on your phone and stay there. your pin, your master key, your item keys, none of them ever reach us.

03

your account signs you in and syncs sealed data. it can’t open your vault, because there is no master key on our side that can.

04

the app carries zero analytics, crash trackers, or ad kits. nothing to opt out of, because nothing is there.

how it stays sealed

plain words,
not a spec sheet.

you do not have to follow the cryptography to trust the outcome. here is what each part actually buys you.

01your pin

slow to guess.

turning your pin into a key is deliberately slow and memory-hungry. a stolen phone does not become a stolen vault.

02your data

tamper-evident.

change one byte of a sealed item and the app rejects it on sight. quietly edited data never reaches you.

03the chip

bound to hardware.

where your phone has a secure chip, your keys live inside it. the system cannot lift them out, and neither can a rogue app.

04at rest

sealed on disk.

everything stored locally is locked with a key that never leaves the device. copy the storage and you copy noise.

05your session

tied to this device.

a stolen token is useless on another phone. every request is signed by a key only your device holds.

06no backdoor

not even for us.

there is no master key on our side and no reset we can run. the honest cost of a vault only you can open.

the limits

what we stop,
and what we can’t.

we would rather mark the edges than sell a perfect shield. no tool covers everything. here is exactly where ours ends.

we protect you from

✓a full server breach. own our servers and database and you still find only ciphertext. no key over here opens it.
✓a database dump. walk off with all of it. sealed blobs, salts, an email, a password hash. nothing that reads your vault.
✓a stolen token. a captured session is useless on another device. every request is signed by a key only your phone holds.
✓a listener on the wire. data is sealed before it leaves the phone. a middleman gets ciphertext.
✓a lost or stolen phone. guesses at your pin are rate-limited and locked by the device. the vault locks, not just the screen.
✓a rogue insider. we cannot hand over your vault, because we were never given a key to it.

we can’t help with

✗a compromised phone. if malware owns android beneath us, nothing running on top can save itself.
✗a keylogger. software that records your pin as you type it beats every guarantee we make.
✗someone watching you type. if a person reads your pin over your shoulder, crypto cannot undo that.
✗being forced to unlock. if you are coerced into opening the vault, the math is not on your side.
✗a forgotten pin. we cannot reset it. the honest price of a vault only you can open.

what we collect

ZERO analytics.
ZERO crash reporters.
ZERO attribution kits.
ZERO third-party sdks.

take the release build apart and you will not find crashlytics, sentry, mixpanel, amplitude, or adjust. the app speaks to our backend and the play integrity check. nothing else, nowhere else.

questions

straight answers.

the things people ask before they trust a vault with everything.

can kaizenstudio see my passwords?

no. your vault is sealed on your phone with a key only you hold. we only ever store data we cannot open.

what happens if your servers are breached?

an attacker finds only sealed data. the key that opens it lives on your device, so a full breach gives up nothing readable.

do i have to trust you?

as little as possible. the design removes our ability to read your vault, so you are trusting the math and your own device, not our promises.

what if i forget my pin?

we cannot reset it, because your pin never reaches us. that is the honest price of a vault only you can open.

is kaizen vault free?

yes. kaizen vault is free during its beta.

which devices does it work on?

android, for now. more platforms are planned.

coming to androidclosed beta

we open slowly,
on purpose.

made by kaizenstudio↗

a password manager is the wrong place to move fast and break things. it is in beta and not yet independently audited, and we would rather say so than hide it. we let people in a few at a time while the security proves itself. leave an email and we will tell you when there is room.

one email when it is ready. no list, no sharing, no follow-ups.

kaizenvault

a password manager we can’t read, by kaizenstudio. android first.

privacytermshow it workslimitscontact
closed beta · by invitation
© 2026 kaizenstudiobuilt in the open, audited before launch