Military-grade AES-256 encryption with zero-knowledge architecture means only you can decrypt your passwords. Learn the technical details of how CredenceX protects your most sensitive information.
Each encryption layer works together to guarantee your passwords stay private
All encryption happens on your device before data is sent to our servers. Passwords are encrypted using your master password. We never receive unencrypted data.
Military-grade encryption algorithm trusted by governments, militaries, and security experts worldwide. Would take billions of years to brute-force.
Each password is encrypted with a unique initialization vector (IV) derived from your master password. Even if two passwords are identical, they encrypt differently.
Our servers store only encrypted data. We have zero ability to decrypt your passwords, even with direct database access or if we wanted to. It's cryptographically impossible.
Type your password into the CredenceX vault on your device.
Your device, your controlYour password is encrypted using AES-256-CBC with a unique key derived from your master password.
Happens on YOUR device—not oursOnly the encrypted password is sent to our servers over industry-standard HTTPS/TLS encryption.
Double encryption in transitThe encrypted password is stored in our database. We cannot decrypt it without your master password.
Zero-knowledge storageWhen you need the password, it's decrypted only on your device using your master password.
We never see the plaintextWe follow industry best practices across every layer of our infrastructure
Every line of code is publicly available on GitHub. Security researchers worldwide can audit and verify our claims.
Independent security experts continuously review our code. Vulnerabilities are identified and fixed responsibly.
You can see exactly what we do with your data. There are no hidden features or secret vulnerabilities.
Community contributions improve security and features. Everyone benefits from shared security knowledge.
Your passwords are encrypted on your device using your master password before any data leaves your device. Only the encrypted data is sent to our servers. Your encryption keys remain only with you. Our servers store encrypted passwords but cannot decrypt them without your master password. Even if we wanted to, it's cryptographically impossible. This is true zero-knowledge.
Since we cannot decrypt your vault without your master password, we cannot help you recover it. This is a feature, not a bug—it guarantees only you can access your passwords. We recommend creating recovery codes during setup and storing them securely. If you lose both, you'll need to create a new vault.
Yes! Our code is completely open source on GitHub. Anyone can review, audit, and verify our claims. This transparency allows the security community to continuously improve our codebase and identify vulnerabilities responsibly.
CredenceX is free to use and always will be. We never charge for core password management functionality. We may offer premium features in the future, but security and privacy remain core and free. We are committed to privacy and will never sell user data or show ads.
No. Absolutely not. Your passwords are encrypted client-side before reaching our servers. Even our team cannot see them. This is by design and is the foundation of our zero-knowledge architecture. Our code is open source—verify it yourself if you don't believe us.
We conduct regular internal security reviews and welcome third-party audits. The open-source nature of our code allows the security community to review and improve it continuously. We take security vulnerabilities seriously and have a responsible disclosure process.
WebAuthn is a W3C standard for hardware-backed authentication using biometric data (fingerprints, face recognition). Your biometric data never leaves your device. Only a cryptographic public key is stored on our servers. This provides authentication without us ever seeing your biometric data.
Even if our servers were compromised, attackers would only get encrypted password data. Without your master password, the data is useless. Plus, we have intrusion detection, regular security audits, and open-source code that the community watches constantly.
Experience military-grade security with zero compromise on privacy or usability.