| Vault storageWhere your encrypted vault physically lives |
Local, on your own device. The encrypted vault data sits in the PNG carrier or in separate file-vault containers and is never transmitted to BlindLock. |
Cloud |
Cloud |
Cloud (self-host possible) |
Cloud |
Local only (KDBX file) |
| Account & loginWhat unlocks the account and vault |
No vault cloud account — carrier + password + device |
Email + master password |
Email + password + Secret Key |
Email + master password (passkey login available) |
Proton account (email + password) |
No account — password/key file |
| Steganographic vaultVault concealed in an ordinary-looking file (deniability depends on threat model) |
PNG carrier with an optional decoy region |
— |
— |
— |
— |
— |
| Risk from copied vault dataWhat an attacker can work on offline, and what they still need in order to unlock it |
BlindLock keeps no customer vaults on a central server. A stolen PNG file on its own does not open the vault hidden inside it. That vault is sealed to the hardware of the authorised device through TPM 2.0, Secure Enclave or StrongBox/TEE, and your password is required on top. The local vault data is also authenticated-encrypted with AES-256-GCM and XChaCha20-Poly1305, one after the other. |
Central encrypted vaults can be bulk-stolen offline |
Central vaults — PQ hybrid TLS on web transport (not vault-at-rest) |
Central encrypted vaults (self-host possible) |
Central encrypted vaults |
Local file only — no provider vault server |
| Hardware-bound keysKey material anchored in platform security hardware |
TPM 2.0 / Secure Enclave / Android StrongBox or TEE where available |
— |
Device-linked (cloud-backed) |
— |
Device-linked |
No hardware sealing (KeePassXC: quick unlock only) |
| Hardware-bound unlockVault key material is sealed to platform security hardware on the authorised device |
Sealed to TPM 2.0, Secure Enclave or a mobile hardware root of trust. The PIN governs unlocking the app. |
— |
— |
— |
— |
— |
| No central vault databaseWhether vault contents are transmitted to the provider |
No vault upload — only a brief licence and version check |
Server-side vault |
Server-side vault |
Server-side (self-host possible) |
Server-side vault |
Local file — no provider vault server |
| Key derivationWhat a single brute-force guess costs the attacker (time × memory) |
Argon2id, memory-hard (512 MiB–4 GB by device class) |
PBKDF2 — not memory-hard, GPU-friendly |
PBKDF2 + SRP — not memory-hard |
PBKDF2 (600k) default for many accounts — Argon2id available (~32–64 MiB) |
bcrypt + SRP — low memory cost per guess |
KeePassXC: Argon2 (~64 MB default) / KeePass 2.x: AES-KDF by default |
| Verifiability of the cryptographyWhether the cryptographic building blocks in use can be inspected publicly |
BlindLock uses the open-source libcrux AEAD building blocks AES-256-GCM and XChaCha20-Poly1305. Formally verified are the AES-256-GCM core and the ChaCha20-Poly1305 core that XChaCha20-Poly1305 builds on. |
Closed |
Closed |
Open source |
Partially open |
Open source |
| TOTP 2FA built inNo second authenticator app needed |
Built in — codes stay inside the vault |
Free plan includes TOTP. Advanced or hardware-backed MFA is often on a paid tier. |
Built in |
Paid tier (Premium) |
Paid tier (Plus) |
KeePass 2.x: third-party plugin required / KeePassXC: built in |
| Pricing modelOne-time vs. recurring revenue |
Lifetime licence with a single payment for one desktop device at a time. iOS and Android are always free for everyone. |
Subscription |
Subscription |
Subscription (free tier) |
Subscription (free tier) |
Free (open source) |
| Selected publicly documented incidentsMajor incidents involving vault or customer data |
No central vault server. To date, no comparable incident has been publicly documented. |
2022 — encrypted vault backups stolen (~30M reported) — cracking linked through 2025 |
No vault exfiltration |
No vault exfiltration |
No vault exfiltration |
No central provider vault |