| Vault storageWhere your encrypted vault physically lives |
PNG carrier; separate file-vault containers |
Cloud |
Cloud |
Cloud (self-host possible) |
Cloud |
Local only (KDBX file) |
| Account & loginWhat unlocks the account and vault |
No vault cloud account — carrier + password + device |
Email + master password |
Email + password + Secret Key |
Email + master password (passkey login available) |
Proton account (email + password) |
No account — password/key file |
| Steganographic vaultVault concealed in an ordinary-looking file (deniability depends on threat model) |
✓ — PNG carrier; optional decoy region |
— |
— |
— |
— |
— |
| Long-term ciphertext riskHarvest-now / decrypt-later exposure if vault ciphertext is bulk-stolen |
No central vault DB to harvest; at rest: 256-bit authenticated encryption (AES-256-GCM + XChaCha20-Poly1305) |
Central encrypted vaults can be bulk-stolen offline |
Central vaults; PQ hybrid TLS on web transport (not vault-at-rest) |
Central encrypted vaults (self-host possible) |
Central encrypted vaults |
Local file only — no provider vault server |
| Hardware-bound keysKey material anchored in platform security hardware |
TPM 2.0 / Secure Enclave / Android StrongBox or TEE where available |
— |
Device-linked (cloud-backed) |
— |
Device-linked |
No hardware sealing (KeePassXC: quick unlock only) |
| Hardware-bound unlockVault key material is sealed to platform security hardware on the authorised device |
✓ — sealed to TPM 2.0 / Secure Enclave / mobile hardware root; PIN gates unlock in the app |
— |
— |
— |
— |
— |
| Central customer-vault databaseWhether the provider stores encrypted customer vaults |
None — vault contents are never sent to BlindLock |
Server-side vault |
Server-side vault |
Server-side (self-host possible) |
Server-side vault |
Local file; no provider vault server |
| Key derivationWhat a single brute-force guess costs the attacker (time × memory) |
Argon2id, memory-hard (512 MiB–4 GB by device class) |
PBKDF2 — not memory-hard, GPU-friendly |
PBKDF2 + SRP — not memory-hard |
PBKDF2 (600k) default for many accounts; Argon2id available (~32–64 MiB) |
bcrypt + SRP — low memory cost per guess |
KeePassXC: Argon2 (~64 MB default) / KeePass 2.x: AES-KDF by default |
| Open cryptographic layerWhether crypto primitives or the full app are publicly inspectable |
libcrux-backed AEAD primitives (verified cores where available); app not open source |
Closed |
Closed |
Open source |
Partially open |
Open source |
| TOTP 2FA built inNo second authenticator app needed |
Built in — codes stay inside the vault |
Free plan includes TOTP; advanced/hardware MFA on paid tiers |
✓ |
Paid tier (Premium) |
Paid tier (Plus) |
KeePass 2.x: third-party plugin required / KeePassXC: built in |
| Pricing modelOne-time vs. recurring revenue |
Lifetime desktop licence (pay once; one active desktop; moves to a new PC; iOS & Android always free, for everyone) |
Subscription |
Subscription |
Subscription (free tier) |
Subscription (free tier) |
Free (open source) |
| Public breach historyMajor disclosed vault exposure |
No central vault service to breach |
2022 — encrypted vault backups stolen (~30M reported); cracking linked through 2025 |
No vault exfiltration |
No vault exfiltration |
No vault exfiltration |
No central provider vault |