Local-first

Local-first password manager

BlindLock starts with your device, not a provider cloud. The complete password vault stays encrypted inside a PNG carrier and opens only when the file, master password and authorised device match.

No silent sync

No permanent cloud sync that creates another attack surface.

One desktop device per licence

Paid Lifetime covers one active Windows, macOS or Linux device. iOS and Android are always free.

Local by design

Local use is not a limitation. It is the security decision.

When local-first is better

  • When you do not want admin passwords or recovery material in browser extensions.
  • When you do not want a provider cloud account holding your vault contents.
  • When you want to control backups yourself.

When cloud may still fit

If your top priority is seamless sync across many devices, a cloud manager may be more convenient. BlindLock chooses local control and reduced central attack surface instead.

Where your data actually lives

For BlindLock, local-first is an architecture decision about where the data sits, not a marketing phrase. Your password, note and 2FA entries live inside an encrypted PNG carrier on your device. Larger documents and media use separate disguised, encrypted file-vault containers. BlindLock servers hold no copy, and no automatic vault-sync service moves either storage type.

At rest, the contents stay encrypted. They are decrypted only when you unlock, and only in memory, for as long as the vault is open. Close the app or lock the device and the decrypted state leaves memory again. What remains on disk is the ordinary-looking carrier file, with no fixed BlindLock header or vault marker that advertises the concealed contents.

These terms answer different questions. “Local” describes where vault contents live: on storage you control. “Cloudless” means there is no central customer-vault database or automatic vault sync. “Offline” needs a narrower definition: activation and every new unlock require licence and version checks, while an opened vault continues locally until the session closes.

Who it is for

  • People who want to know exactly where their most sensitive logins are stored, rather than trusting them to someone else's data centre.
  • Anyone holding high-value credentials or recovery material who wants to avoid the risk of a central provider vault.
  • Users who prefer to choose their own backup location: local storage, external media or an optional cloud-synchronised folder.

Who it is not for

  • If you expect real-time sync across five devices without moving a file yourself, a classic cloud service fits better.
  • If you need to share and centrally manage passwords across a team, the "one licence, one device" rule is not the right shape for you.
  • If you never want to make a backup: local control also means local responsibility for that backup.

A day with a local vault

You open your laptop in the morning and unlock the vault with the carrier file and your password. The device itself is the third factor, anchored through TPM 2.0, Secure Enclave or StrongBox, depending on the platform. While the vault is open you copy a password to the clipboard and read a 2FA code (TOTP, a time-based one-time password).

In the afternoon you lock the vault. The decrypted contents leave memory, and no vault contents have been uploaded to BlindLock. In the evening you back up the carrier and create an encrypted BlindLock backup for migration. You keep the recovery phrase separately.

What BlindLock does not claim here

Local does not mean invulnerable. A compromised operating system, malware with memory access during an open session, or a lost recovery phrase remain real risks. BlindLock removes the central provider attack surface and hides the vault inside an unremarkable file, but it makes no magical promise of all-round protection. Steganography is an added layer of concealment, not a theft-proof guarantee.

Frequently asked

Does my vault ever sit on a BlindLock server?

No. BlindLock operates no central customer-vault database or automatic vault-sync service. The encrypted carrier stays on storage you control unless you deliberately copy or export it.

Where is my password decrypted?

Only in your device's memory, and only while the vault is open. Once it closes, all that remains on disk is the encrypted file.

How do I back up a local vault?

Back up the active carrier. For device migration and emergencies, also create an encrypted BlindLock backup and keep the recovery phrase separately. If you use file vaults, back up each container with its recovery file and recovery factor.

How is "local" different from "offline" and "cloudless"?

“Local” describes where vault contents are stored. “Cloudless” describes the absence of a central customer-vault service. “Offline” does not mean the app never connects: every new unlock needs a licence and version check.

Next step

Does this local-first setup fit you? Then claim one of the 1,000 lifetime licences. One licence covers one active device; prices rise in three phases from €59 to €79 to €99, after which the subscription is €4.99 per month or €39.99 per year.