Security & Encryption: How Your Passwords Stay Private

Military-grade AES-256 encryption with zero-knowledge architecture means only you can decrypt your passwords. Learn the technical details of how CredenceX protects your most sensitive information.

AES-256Zero-KnowledgeOpen SourceEnd-to-End Encrypted

Security By The Numbers

AES-256
Military-Grade Encryption
Would take billions of years to brute-force with current technology
10+
Bcrypt Hash Rounds
Exponentially increases computational cost of password attacks
100%
Client-Side
All encryption happens on your device before data is sent
Our Access
We have zero ability to decrypt your passwords

Four Pillars of Your Protection

Each encryption layer works together to guarantee your passwords stay private

Client-Side Encryption

All encryption happens on your device before data is sent to our servers. Passwords are encrypted using your master password. We never receive unencrypted data.

This is the foundation of zero-knowledge architecture

AES-256-CBC Standard

Military-grade encryption algorithm trusted by governments, militaries, and security experts worldwide. Would take billions of years to brute-force.

The same encryption used by US government and NATO

Unique Encryption Keys

Each password is encrypted with a unique initialization vector (IV) derived from your master password. Even if two passwords are identical, they encrypt differently.

Prevents pattern recognition attacks

Zero-Knowledge Design

Our servers store only encrypted data. We have zero ability to decrypt your passwords, even with direct database access or if we wanted to. It's cryptographically impossible.

Your encryption keys never leave your device

Your Password Encryption Flow

1

You Enter Your Password

Type your password into the CredenceX vault on your device.

Your device, your control
2

Local AES-256 Encryption

Your password is encrypted using AES-256-CBC with a unique key derived from your master password.

Happens on YOUR device—not ours
3

Secure HTTPS/TLS Transmission

Only the encrypted password is sent to our servers over industry-standard HTTPS/TLS encryption.

Double encryption in transit
4

Secure Storage

The encrypted password is stored in our database. We cannot decrypt it without your master password.

Zero-knowledge storage
5

Decryption on Retrieval

When you need the password, it's decrypted only on your device using your master password.

We never see the plaintext

Comprehensive Security Practices

We follow industry best practices across every layer of our infrastructure

Authentication

  • Bcrypt password hashing (10+ rounds)
  • JWT tokens with 7-day expiration
  • Automatic session timeout after 5 minutes of inactivity
  • Optional WebAuthn/FIDO2 biometric authentication
  • Two-factor authentication support
  • Secure password recovery mechanisms

Data Protection

  • HTTPS/TLS encryption for all communications
  • No plaintext password storage anywhere
  • Encrypted database backups
  • Regular third-party security audits
  • Intrusion detection systems
  • Database access controls and logging

Privacy

  • No user tracking or analytics
  • No third-party data sharing
  • GDPR and international compliance
  • User data deletion on request (right to be forgotten)
  • Privacy-by-design architecture
  • Minimal data collection policy

Infrastructure

  • Regular security patches and updates
  • DDoS protection and rate limiting
  • SQL injection prevention
  • XSS (Cross-Site Scripting) protection
  • CSRF (Cross-Site Request Forgery) protection
  • Secure API design with authentication

Why Open Source Security Matters

Full Transparency

Every line of code is publicly available on GitHub. Security researchers worldwide can audit and verify our claims.

Community Verification

Independent security experts continuously review our code. Vulnerabilities are identified and fixed responsibly.

No Hidden Backdoors

You can see exactly what we do with your data. There are no hidden features or secret vulnerabilities.

Continuous Improvement

Community contributions improve security and features. Everyone benefits from shared security knowledge.

Security Questions

How does zero-knowledge encryption really work?

Your passwords are encrypted on your device using your master password before any data leaves your device. Only the encrypted data is sent to our servers. Your encryption keys remain only with you. Our servers store encrypted passwords but cannot decrypt them without your master password. Even if we wanted to, it's cryptographically impossible. This is true zero-knowledge.

What if I forget my master password?

Since we cannot decrypt your vault without your master password, we cannot help you recover it. This is a feature, not a bug—it guarantees only you can access your passwords. We recommend creating recovery codes during setup and storing them securely. If you lose both, you'll need to create a new vault.

Is CredenceX open source? Can I audit the code?

Yes! Our code is completely open source on GitHub. Anyone can review, audit, and verify our claims. This transparency allows the security community to continuously improve our codebase and identify vulnerabilities responsibly.

How do you make money if the app is free?

CredenceX is free to use and always will be. We never charge for core password management functionality. We may offer premium features in the future, but security and privacy remain core and free. We are committed to privacy and will never sell user data or show ads.

Can you see my passwords?

No. Absolutely not. Your passwords are encrypted client-side before reaching our servers. Even our team cannot see them. This is by design and is the foundation of our zero-knowledge architecture. Our code is open source—verify it yourself if you don't believe us.

How often is the code audited for security?

We conduct regular internal security reviews and welcome third-party audits. The open-source nature of our code allows the security community to review and improve it continuously. We take security vulnerabilities seriously and have a responsible disclosure process.

What is WebAuthn/FIDO2 biometric authentication?

WebAuthn is a W3C standard for hardware-backed authentication using biometric data (fingerprints, face recognition). Your biometric data never leaves your device. Only a cryptographic public key is stored on our servers. This provides authentication without us ever seeing your biometric data.

What happens if CredenceX gets hacked?

Even if our servers were compromised, attackers would only get encrypted password data. Without your master password, the data is useless. Plus, we have intrusion detection, regular security audits, and open-source code that the community watches constantly.

Biometric Authentication (WebAuthn)

How It Works

  • Your biometric data (fingerprint, face) stays on your device
  • Only a cryptographic public key is stored on our servers
  • Authentication happens through cryptographic verification
  • We never see, store, or have access to your biometric data

Security Benefits

  • Faster, more convenient than password-only login
  • Hardware-backed keys prevent credential theft
  • Works with devices that have biometric sensors
  • Falls back to password authentication as needed

Our Security Promises

We will never encrypt your data for ransom
We will never add backdoors for law enforcement
We will never sell or share your data
We will never use your data for advertising
We will never stop maintaining security updates
We will always be transparent about breaches

Ready to Secure Your Passwords?

Experience military-grade security with zero compromise on privacy or usability.