Security

A zero-knowledge password manager, explained in plain words — and then in detail

Two versions of the same page. The first is for anyone. The second links to the documents an auditor reads, because that is where the real claims live.

In plain words

Your vault never touches our servers

That is why it cannot be breached by us, and it is why there is no monthly bill: no servers to run means no rent to charge. Your secrets live in one encrypted file that you hold, on the devices you own, synced through the cloud storage you already pay for. We wrote the software. The secrets are yours.

You should be in control of your secrets

Not a company that can be breached, not a cloud that can be handed over, not a subscription that can lapse the week you need it. Every breach headline is the same reminder: the safest place for the things that cannot be reset is a file you hold, sealed with a key only you have. That is what this is.

Two secrets, not one

Your vault is sealed with XChaCha20-Poly1305 under a key that Argon2id derives from your master password and a 128-bit Secret Key that only you hold. Steal the file, a sync blob or a backup, and an attacker still faces 2128 work — even if your master password was weak. The Secret Key never enters the vault file, a sync payload, a log line or a synchronizable keychain, and a test fails the build if it ever does.

It is a local file you own

If TigerCodes vanished tomorrow, the format is documented to the byte and the export is lossless. Nobody can lock you out of your own secrets — including us.

The newest defenses

Unlock with a hardware security key

Touch a FIDO2 key — a YubiKey or any of its cousins — instead of typing your master password, on Mac, Windows and Linux. The key never becomes the root of your vault: your password still works, still recovers, and is still asked for on the things that matter most. The key must verify you (its PIN or its fingerprint) — presence alone is not enough. Enroll up to five keys, revoke any of them. Verified against the specification end to end; the round trip on physical keys is the last checklist item before 1.0.

Passkeys with keys that can never be shown

Keep passkeys next to your passwords and sign in with them from the browser extension and on Android, with iPhone and Mac following as soon as signed builds are verified. A passkey's private key has no reveal button, no copy button and no place in search: it signs for its own site and does nothing else, so a lookalike site gets nothing even if you are fooled.

Sync straight to Google Drive or OneDrive — or iCloud Drive, Dropbox, Syncthing, any folder

No tigerpassword server in the middle, ever. What lands in your cloud is ciphertext and a signed manifest, never a title, never a key. The app refuses to act on a provider that misbehaves — a missing or garbled listing never reads as "delete everything" — and when two devices edit the same item, both versions are kept rather than one silently winning.

Backups that are always encrypted, to wherever you trust

Your own folder, a WebDAV server such as Nextcloud, an S3 bucket, or an SFTP box whose host key you pin on first use — present a different key later and the connection is refused before a single credential is sent. There is no plaintext-backup switch in the app because there is no plaintext-backup code path.

A breach check that never sends your password

Vault Health asks Have I Been Pwned about the first five characters of a hash — the k-anonymity protocol — and does the matching on your device. Reused, weak and stale passwords are graded locally, and the strength numbers are honest upper bounds, not flattery.

Deep search that never writes an index

Find an item by any field you can see. Hidden values never take part in search, and nothing is written to disk to make it fast.

Builds you can reproduce

The toolchain is pinned and the command-line tool builds bit-for-bit identically from two independent copies of the source — CI checks it on every change, so an independent builder reaches the published hash. Seventeen fuzz targets hammer every parser that touches untrusted input: imports, backups, sync listings, QR codes. The key-derivation parameters inside any file you open are capped, so a doctored vault cannot talk the app into a cheap unlock.

Phones, and the keychain

On iPhone the vault key rests in the keychain behind Face ID / Touch ID, device-only and never synchronized — so the phone's autofill can open the vault without the password ever touching the extension. Android remembers the Secret Key sealed under a hardware-keystore key in storage that is excluded from every backup. Both phones lock when you leave the app.

Built for the secrets you can't afford to lose

A crypto recovery phrase, a hardware-wallet seed, the backup codes for your two-factor login, a passkey that is the only way into an account. tigerpassword treats them as a different class of thing:

  • Seed phrases are checked word by word against the official BIP-39 word lists as you type. The checksum is never skipped to make a save go through, and Electrum, Monero and SLIP-39 phrases are recognized for what they are instead of being marked wrong. A phrase that does not verify is saved with a visible warning badge — never silently.
  • Seeds are never autofilled, anywhere. The browser extension and the phone autofill services cannot ask for them, and the core refuses even if they did. They never take part in search. Revealing one on screen is a deliberate act: amber, with a draining ring, hidden again after thirty seconds.
  • Backups are encrypted, always, with an optional memorized passphrase for the day you have neither device nor key. Sync providers, backup destinations and imported files are all treated as hostile input.

Breaches are not slowing down. Your passwords must stop being the weak link.

Every breach headline is the same reminder: a password reused anywhere is a password lost everywhere. Publicly reported data compromises in the United States nearly tripled between 2020 and 2024, and 2024 alone produced more than a billion victim notices.

US data compromises per year, 2020–2024: 1,108 rising to 3,158 (+185%). Source: Identity Theft Resource Center annual data breach reports.
The numbers
YearCompromisesVictim notices
20201,108301 million
20211,862294 million
20221,802422 million
20233,205353 million
20243,1581.35 billion

Source: Identity Theft Resource Center, Annual Data Breach Reports 2020–2024. Counts are publicly reported compromises affecting US residents; victim notices count notifications, not unique people.

What a breach can and cannot take from you

  • One unique password per site means a breached site leaks a password that opens nothing else. That is the whole point of a manager, and the generator makes it effortless.
  • Passkeys cannot be phished or replayed. A passkey signs for its own site only; a leaked database of passkey public keys is useless to an attacker.
  • Vault Health tells you which passwords already appeared in a breach — checked against Have I Been Pwned without ever sending your password.
  • And the vault itself is not a target. There is no tigerpassword server to breach: your encrypted file lives on your devices, sealed with two secrets only you know.

How the vault stays private

For engineers: security you can check

The documents an auditor reads exist, and are shared with auditors and serious evaluators on request through the contact page. Cryptography comes only from pinned, widely reviewed libraries; nothing is home-grown, and known-answer tests pin every primitive to its RFC so a bad dependency update fails loudly instead of quietly.

DocumentWhat it answers
Threat modelWho we defend against, what we do not, and the assumptions behind every promise on this page.
Crypto specificationByte layouts, key derivation (Argon2id per RFC 9106), the AEAD (XChaCha20-Poly1305), sync and backup formats, keychain custody, hardware-key wrapping.
Audit scopeEvery invariant mapped to the test that enforces it — the document the auditor starts from.
Pre-audit reviewWhat was swept, what was fixed, and what was left open, before anyone outside looked.
Security policyHow to report a vulnerability, response times, and how to verify a build reproduces.
Export formatThe lossless export that guarantees you can always leave.

Standards the design rests on

  • Argon2id — RFC 9106, including the secret-input parameter for the Secret Key; parameters from files are capped.
  • XChaCha20-Poly1305 — draft-irtf-cfrg-xchacha; every record authenticated with its own additional data.
  • BIP-39 word lists and checksums, verbatim upstream; SLIP-39, Electrum and Monero detection.
  • WebAuthn / FIDO2 (CTAP2 hmac-secret) for hardware-key unlock and passkeys; ES256.
  • Password guidance per NIST SP 800-63B; the interface per WCAG 2.2 AA.

Reporting a vulnerability

Email us with "SECURITY" in the subject: (shown with JavaScript on; or use the contact form). You will receive an acknowledgment within 72 hours and a resolution timeline within 14 days; coordinated disclosure is honored. Details in security.txt.

Questions people ask

Can TigerCodes read my vault?

No. Your vault is encrypted on your device with a key derived from your master password and a Secret Key that only you hold. There is no tigerpassword server, so nothing is sent to us to read.

What happens if I forget my master password?

Your vault cannot be opened — by you, by us, by anyone. That is what zero-knowledge means. Keep your printed Recovery Kit and choose a master password you will remember.

What is the Secret Key?

A 128-bit random key generated on your device when you create the vault and printed on your Recovery Kit. Together with your master password it seals the vault, so a stolen file is useless even if the password was weak. It never enters the vault file, a sync payload, a backup or a log.

Has tigerpassword been audited?

Not yet. An independent audit is the headline use of the Kickstarter funds. Until it lands, the security policy asks you not to store real credentials or seed phrases.

Help fund the audit All features