One name
David Domingo. No ticketing system with a department behind it. If something goes wrong, there is nobody I can point at.
BlindLock is built by one person. If you are going to hand a vault your secrets, you should know who you are trusting — and what I cannot prove to you.
David Domingo. No ticketing system with a department behind it. If something goes wrong, there is nobody I can point at.
Nobody asks me for usage figures, because there is nobody I owe growth to. That is why BlindLock collects nothing.
My own credentials have lived in this software since November 2025. I am the first person any mistake reaches.
It did not start as a product. I wanted a vault I trusted myself, and I could not find one. Every one I tried asked for trust somewhere I was not willing to give it — an account with the provider, a copy of my data on someone else's servers, a statement instead of an architecture.
So I started building my own. For myself, at first. Then it got better, because I used it every day and every day I found something that bothered me. Today my digital life sits inside it, and it has become good enough that I want to offer it to other people.
Two things about me belong out in the open, because they explain where that thoroughness comes from. I am mistrustful by nature, to a degree that is sometimes exhausting in ordinary life. And I have a mild form of autism, Asperger's. In practice that means I cannot leave a detail alone once it does not fit. I will walk through a process twenty times until no case is left open, and start again when I find one after all.
In daily life that is a burden. For a vault it is the right disposition.
What you buy here comes first and foremost from a person. Formally there is a company above it, BlindLock, LLC — that is the legal form the sale runs through. I do want to earn money with it, and there is nothing wrong with that. But the order matters: this is my project first, my hobby, my passion, the thing all my heart goes into — and a product second.
The difference is not a question of diligence. There are excellent developers inside companies, and I am not going to claim they are less capable or work less hard. Many of them work with real passion and are proud of their product. The difference is structural: there, the product is a means, and the company's commercial success hangs on it. Here it is the purpose.
Someone who spots a weak point one evening has to defend it on Monday against a roadmap, quarterly targets and other people's priorities. That authority does not exist here. When something strikes me as improvable, I build it and stop only when I am satisfied. Then I question it again from other angles until I know it holds.
I use BlindLock myself, every day. If I overlook a weakness or build something in wrongly, I am the first to lose.
I put every free minute into this project. Not because a plan demands it, but because I cannot do otherwise.
I burn for this. That is not a line for a website, it is the reason this software exists at all.
This is the point where experienced people look hard at a closed vault, and they are right to. So I will say it myself before anyone uncovers it: BlindLock has not been examined by an external auditor.
The reason is money, not reluctance. A serious audit of a crypto stack runs into five figures. I do not have that before the first sale. I could buy a cheap certificate that looks good and checks nothing. That would be a lie.
As soon as BlindLock earns revenue, part of it goes into an external review of the cryptographic core, and the result lands on this page. Including the uncomfortable parts.
You cannot read my source code. BlindLock is not open, and I am not going to claim that you should therefore simply believe me.
What I can offer instead is architecture rather than promises. There is no central vault database. Your vault contents sit on your device and are not transmitted to my servers. That means nothing exists for me to hand over — not to an authority, not to an attacker, not to some future buyer of this company. A backdoor into a vault whose contents I never see would have no target.
On top of that sits the hardware binding. Even with your carrier file and your password in hand, the vault opens only on your device, because the key is sealed to that device's security chip.
Most providers collect usage data because somebody inside the company needs it. An investor wants to see growth, a marketing team wants segments, a product manager wants click paths.
Those people do not exist here. There is no telemetry in BlindLock, no analytics scripts on this website and no hidden measurement. Not out of generosity, but because nobody is around to demand it.
Secure enough today does not mean secure enough in two years. Attacks improve, hardware gets faster, assumptions fall. Security software that rests on its current state is on its way to becoming insecure.
I will not coast on whatever success this software finds. That is not a marketing line, it is the only working attitude that is defensible for a vault.