Your AI gets its own vault. Not yours.
Give each assistant a separate vault with only the logins it needs. It signs in with single-use handles instead of the password, and its key can’t open your personal vault.
iPhone · Chrome, Brave and other Chromium browsers · Linux
A sample session: an assistant asks for a login, gets a single-use handle that expires after 60 seconds by default, types it into the site once and signs in, with the password kept out of the chat.
5EqGdXoFS7TJSf7Z9Z3tgbp5IczXN+g8wpbAy1ZqCV29BnThFMwmUSOOsaG5V3nTuJ3Tf2zLnWknvB8xEqioUPNnjBV5hUNYERZQIDrmF2XDBTPbQdjkeOwDd0yn5kkxzx1hSEjesyZYQmP/kd0TlShYT2oHYPpKEXNI515Wvf/xYB369kBhWSo+lBIMCLqQhhgEHZAa0nBbdapmLFRUsno4mqjAS34m80qKyvd3H+8=
One vault for you. A separate one for each assistant.
For you
Logins, notes and two-factor codes on iPhone and Linux. Logins and two-factor codes in Chrome, Brave and other Chromium browsers. Passkeys and Face ID on iPhone. Save a login on one device and it shows up on the others.
For your assistants
An MCP server, a command line and agent vaults with their own keys. An assistant uses logins through single-use handles, so in normal use the password stays out of the chat and the logs. Revoke its access at any time. For developers
Locked and opened on your device.
- STEP 1
Encrypted before it leaves
XChaCha20-Poly1305 on your device, under a key stretched from your master password with Argon2id.
- STEP 2
The key stays with you
Your master password or your recovery key opens the vault. We can’t reset your password, and we can’t read your vault.
- STEP 3
Assistants get a handle
A single-use handle that expires after 60 seconds by default. Used once, then gone.
Your vault reaches us as ciphertext.
During the beta, vaults sync through a service we run on a machine we operate in Perth, Australia, with its own data and keys. It isn’t a dedicated host. Traffic to it passes through Cloudflare. Here is what the server can and can’t see.
We can’t see
- Your items, usernames and passwords
- Notes, folder names, passkeys and two-factor seeds
- Your master password, or any key that opens your vault
We can see
- Your email address
- Device names and types, and when each last connected
- How many items you have, their sizes and when they change
- Your IP address when a device connects
Built and tested today. Beta means it’s still changing.
All 43 features.
Security and privacy
End-to-end encrypted vault
READYItems are encrypted on your device with XChaCha20-Poly1305 before they are stored or synced.
Linux · iPhone (Beta) · Chromium browsers (Beta)
Master password hardening
READYYour master password is stretched with Argon2id (256 MiB, 3 passes at minimum). Weaker settings are refused.
Linux · iPhone (Beta) · Chromium browsers (Beta)
Zero-knowledge
BETAThe server stores ciphertext. It can't read your items, folder names or keys, and it never receives your master password.
Tamper detection
BETAUploads are signed by the device and checked on download. A modified vault is refused, and on a normal sync so is one rolled back below what that device has seen.
Linux · iPhone · Chromium browsers
Auto-lock
READYThe vault locks after a period of inactivity and can be locked on demand. On Linux, an unlock from the command line lasts until you lock it again.
Linux · iPhone (Beta) · Chromium browsers (Beta)
Passwords and logins
Logins and secure notes
READYIn a local vault on your computer, create, edit and search logins and notes. With an account, the command line adds and reads them.
Linux
Folders and favourites
BETAOrganise items into folders and mark favourites.
iPhone
Password and passphrase generator
BETAGenerates random passwords or word-based passphrases with the options you choose.
iPhone
Two-factor codes
READYStores authenticator seeds and shows the current six-digit code.
Linux · iPhone (Beta) · Chromium browsers (Beta)
Passkeys
BETAStores passkeys and signs you in with them on iPhone.
iPhone
SSH keys
READYStores SSH keys as vault items.
Linux
Vault health
BETAFlags reused and weak passwords. The check runs on your iPhone.
iPhone
Import
READYImport logins, notes, cards, identities and passkeys from one other password manager's JSON export. Other export formats are not supported yet.
Linux
Encrypted export
READYWrite the whole vault to an encrypted file, or to an encrypted .kdbx database you can open in other tools.
Linux
Autofill and browser
Browser autofill
BETAFills a login on the domain it was saved for, subdomains included. It takes the last two parts of the address as the domain (three for some endings, such as .co.uk), so two sites on github.io count as one.
Chromium browsers
In-page suggestions
BETAA menu beside the username and password fields offers the matching logins.
Chromium browsers
Save new logins
BETAOffers to save a login after you sign in somewhere new.
Chromium browsers
Two-factor code fill
BETAFills the current two-factor code into the page's code field.
Chromium browsers
Browser extension sign-in
BETAThe browser extension signs in with your email and master password and syncs your vault, with no other software to install.
Chromium browsers
Phones
iPhone app
BETABrowse, search and use your vault on iPhone.
iPhone
iPhone AutoFill
BETAFills passwords, one-time codes and passkeys in apps and Safari.
iPhone
Face ID and Touch ID
BETAUnlock with Face ID or Touch ID. Changing the enrolled biometrics requires the master password again.
iPhone
Add and edit on iPhone
BETACreate and edit logins on the phone. Changes sync to your other devices.
iPhone
Devices and sync
Sync across devices
BETAChanges made on one device appear on your others automatically.
iPhone · Chromium browsers · Linux
Simultaneous edits are merged
BETAEdits made on two devices at the same time are merged item by item. A true conflict keeps both copies.
Linux · iPhone · Chromium browsers
Device management
BETASee your signed-in devices and sign any of them out.
Linux
Accounts and recovery
Email and master password
BETACreate an account and sign in on each device with your email and master password. No QR code.
Linux · iPhone · Chromium browsers
Recovery kit
BETAA recovery key is shown once at sign-up. With it you can set a new master password if you forget yours. We can't open your vault for you without one.
Linux · iPhone · Chromium browsers
Recovery waiting period
BETAA recovery waits 72 hours before it can complete. Until then, the iPhone app shows it in Settings and the command line shows it in account status, and either can cancel it.
Linux · iPhone
Change master password
BETAChanging the master password signs out every other device.
Linux
AI assistants and developers
MCP server
READYGives AI assistants tools to find, use and add credentials, with the secret kept out of each tool's reply.
Linux
Single-use handles
READYAn assistant gets a one-time handle, not the password. It expires after 60 seconds by default.
Linux
Materialise to file
READYA secret is written to a temporary file with owner-only permissions, and deleted when it expires. It isn't put into the conversation, a command line or our logs.
Linux
Redacted reads
READYListing and viewing items shows passwords and other secret fields as [PROTECTED] instead of the value. Names, usernames, site addresses and notes that don't look like secrets are shown.
Linux
Leak contract
READYA test sweeps a marker secret through each command, tool, log and error, and fails the build if any one of them returns it. It checks each tool on its own.
Linux
Fill browser fields for an assistant
READYTypes a secret straight into a field in a browser you opened for remote debugging, so the value stays out of the conversation. It doesn't yet check that the page is the site the login was saved for.
Linux
Two-factor codes for assistants
READYAn assistant can have a current two-factor code typed into a page without the code or the seed being returned to it.
Linux
Ask the owner for a secret
READYAn assistant can ask you for a credential through a one-time form. The value goes straight into the vault.
Linux
Audit trail
READYKeeps an append-only, value-free record of login activity.
Linux
Command line
READYCreate, list, unlock and sync a vault from the terminal. Secrets are read from files, never from arguments.
Linux
Desktop app for Linux
READYA tray app to unlock, search, add and edit items in a local vault on your computer. It does not open an account vault yet.
Linux
Agent vaults
BETAEach assistant works from its own separate vault with its own key, which can't open your personal vault.
Linux
Scoped agent credentials
BETAIssue an assistant a credential limited to named agent vaults, and revoke it at any time.
Linux
Not yet: Android, family and team sharing, Firefox and Safari. See the gaps
The questions we’d ask too.
Letting software near your passwords should make you suspicious. Here’s what we protect against and what we don’t. What isn’t built yet is listed on the Security page.
Protects against
- Passwords landing in chat history, logs or the command line during normal use
- An assistant with an agent vault opening your personal vault: its key opens its own vault, not yours
- The server, or anyone who breaks into it, reading your vault
- A tampered vault: your devices check the signature on every download
Doesn’t protect against
- An assistant you’ve connected that sets out to read or misuse what’s in the vault you gave it
- Anything running as your user on your computer, including an assistant with shell access
- A web page that tricks your assistant into typing a password into the wrong site
- A weak master password, if someone captures your sign-in key
- A brand-new device being shown an old copy of your vault
Why would I let an AI anywhere near my passwords?
You don’t have to: the vault works without one. If you do connect one, give it its own agent vault with only the logins it needs. Its key can’t open your personal vault, and you can revoke it at any time. Treat a connected assistant as able to see everything in the vault you give it.
Can my assistant read the passwords it uses?
In normal use it gets a single-use handle, a typed field or a short-lived private file, so the password stays out of the chat. That is not a promise against an assistant that sets out to dig for it.
Today a connected assistant can recover a password by chaining our own tools, and one with shell access can read the file we write for it. We’re closing the tool route before we invite testers. Until then, scope its vault to what you’d be fine with it seeing.
What if a web page tricks my assistant?
Today there’s no approval step when an assistant uses a login. Our browser typing tools don’t yet check that the page belongs to the site the login was saved for, and an assistant can change an item’s saved sites. So a hijacked assistant could type a password into the wrong site.
Before we invite testers, assistant fills will be limited to the sites a login was saved for, and changing those sites from an assistant will need your approval. Until then, don’t connect an assistant that browses untrusted pages to a vault holding anything important.
Is it safe to unlock the vault on a computer where AI agents run?
Not yet. On Linux, atlas-vault unlock leaves a key in a file in your home folder until you run atlas-vault lock. Anything running as your user can read it, including an assistant with shell access.
If you run our assistant server as an always-on local service, it accepts any connection from your computer without a token. We’re adding an expiry to that file and a required token before we invite testers. Until then, run assistants as a separate user or in a sandbox, and lock the vault when you’re done.
What does the company running my assistant learn?
To find the right login, an assistant sees item names, usernames, website addresses, identity details and notes that don’t look like secrets. So the company running your assistant learns which services you use.
Our note filter misses some secrets, such as PINs, seed phrases and backup codes, so keep those out of notes on items an assistant can reach. Some replies also include a short hash and the length of a value, which someone holding the chat could use to check guesses at a weak password. We’re hiding notes from assistants and switching to a keyed fingerprint before we invite testers.
Does my master password leave my device?
No. Your device stretches it with Argon2id, at least 256 MiB of memory and 3 passes, and refuses weaker settings even if a server asks for them. It then sends a separate sign-in key derived from it, which can’t decrypt anything. The server stores a hash of that key.
Someone who captured the sign-in key, including Cloudflare, which carries the connection, could try to guess a weak master password offline. Today they could also use it to change your account password or recovery key and lock you out of sync, though not to read your vault. Use a long master password that you use nowhere else.
Who runs the server, and what can it see?
We do, during the beta, on a machine we operate in Perth, behind a Cloudflare tunnel. It’s a separate service with its own data and keys, but not a dedicated host, and its backups are on the same machine for now.
It sees your email, your devices, how many items you have, their encrypted sizes, when they change and your IP address when you connect. It can’t decrypt your vault, but it could withhold or delete it, so keep an encrypted export.
Could the server roll my vault back to an old version?
Partly. On a normal sync, each device remembers the newest version it has seen and refuses an older copy, on Linux, iPhone and the browser extension. A new or reinstalled device has nothing to compare against, and our own review found one Linux sync path that could accept an older signed copy. We’re fixing that path before we invite testers.
Has anyone independent reviewed this? Who wrote it?
Not yet. Atlas Vault is about three months old, and much of it was written with AI coding tools. A change merges when the required automated checks pass, without a second person approving it. The encryption comes from libsodium and the Python cryptography library, not primitives of our own, and every change runs our leak test before it can merge. We’ll commission an independent security review before general availability.
What happens to the email I give the waitlist?
It’s stored in a Supabase database in Singapore with the use you picked, your consent and the time. Cloudflare Turnstile checks you’re a person once you start filling in the form (typing, clicking into the email field or choosing an option, not reading or scrolling past it), and we get a one-line Discord notice with a masked address. To be removed, email contact@atlas-ai.au and we’ll delete your entry by hand. The full list of services is on the Privacy page.
Compared with other password managers.
Where they are ahead, we say so.
| Feature | Atlas Vault | Other password managers |
|---|---|---|
| End-to-end encrypted vault | Available | Standard |
| Zero-knowledge | Beta | Standard |
| Passkeys | Beta | Standard |
| Single-use handles | Available | Some offer it |
| Agent vaults | Beta | Some offer it |
| Android app | Not yet | Standard |
| Family and team sharing | Not yet | Standard |
Sources, checked 2026-10. Each row in the “Other password managers” column rests on at least two published pages from other password managers or the press (30 pages in all). We don’t name other products on this site.
Want in? Leave your email.
We’re letting people in a few at a time. We’ll email you when there’s room, and only about the beta.