Private beta · by invitation

Your AI gets its own vault. Not yours.

Give each assistant a separate vault with only the logins it needs. It signs in with single-use handles instead of the password, and its key can’t open your personal vault.

iPhone · Chrome, Brave and other Chromium browsers · Linux

assistant session

A sample session: an assistant asks for a login, gets a single-use handle that expires after 60 seconds by default, types it into the site once and signs in, with the password kept out of the chat.

assistantneeds a login for login.example.com
vaulthandle av_7f3c·91e2 issued
assistanttyping the handle into login.example.com
vaulthandle used once, now revoked
assistantsigned in. password stayed out of the chat.
What the server storesa sample login · XChaCha20-Poly1305

5EqGdXoFS7TJSf7Z9Z3tgbp5IczXN+g8wpbAy1ZqCV29BnThFMwmUSOOsaG5V3nTuJ3Tf2zLnWknvB8xEqioUPNnjBV5hUNYERZQIDrmF2XDBTPbQdjkeOwDd0yn5kkxzx1hSEjesyZYQmP/kd0TlShYT2oHYPpKEXNI515Wvf/xYB369kBhWSo+lBIMCLqQhhgEHZAa0nBbdapmLFRUsno4mqjAS34m80qKyvd3H+8=

01 · Two kinds of user

One vault for you. A separate one for each assistant.

For you

Logins, notes and two-factor codes on iPhone and Linux. Logins and two-factor codes in Chrome, Brave and other Chromium browsers. Passkeys and Face ID on iPhone. Save a login on one device and it shows up on the others.

For your assistants

An MCP server, a command line and agent vaults with their own keys. An assistant uses logins through single-use handles, so in normal use the password stays out of the chat and the logs. Revoke its access at any time. For developers

02 · How it works

Locked and opened on your device.

  1. STEP 1

    Encrypted before it leaves

    XChaCha20-Poly1305 on your device, under a key stretched from your master password with Argon2id.

  2. STEP 2

    The key stays with you

    Your master password or your recovery key opens the vault. We can’t reset your password, and we can’t read your vault.

  3. STEP 3

    Assistants get a handle

    A single-use handle that expires after 60 seconds by default. Used once, then gone.

03 · What we can see

Your vault reaches us as ciphertext.

During the beta, vaults sync through a service we run on a machine we operate in Perth, Australia, with its own data and keys. It isn’t a dedicated host. Traffic to it passes through Cloudflare. Here is what the server can and can’t see.

We can’t see

  • Your items, usernames and passwords
  • Notes, folder names, passkeys and two-factor seeds
  • Your master password, or any key that opens your vault

We can see

  • Your email address
  • Device names and types, and when each last connected
  • How many items you have, their sizes and when they change
  • Your IP address when a device connects
04 · What works today

Built and tested today. Beta means it’s still changing.

All 43 features.

Security and privacy

  • End-to-end encrypted vault

    READY

    Items are encrypted on your device with XChaCha20-Poly1305 before they are stored or synced.

    Linux · iPhone (Beta) · Chromium browsers (Beta)

  • Master password hardening

    READY

    Your master password is stretched with Argon2id (256 MiB, 3 passes at minimum). Weaker settings are refused.

    Linux · iPhone (Beta) · Chromium browsers (Beta)

  • Zero-knowledge

    BETA

    The server stores ciphertext. It can't read your items, folder names or keys, and it never receives your master password.

  • Tamper detection

    BETA

    Uploads are signed by the device and checked on download. A modified vault is refused, and on a normal sync so is one rolled back below what that device has seen.

    Linux · iPhone · Chromium browsers

  • Auto-lock

    READY

    The vault locks after a period of inactivity and can be locked on demand. On Linux, an unlock from the command line lasts until you lock it again.

    Linux · iPhone (Beta) · Chromium browsers (Beta)

Passwords and logins

  • Logins and secure notes

    READY

    In a local vault on your computer, create, edit and search logins and notes. With an account, the command line adds and reads them.

    Linux

  • Folders and favourites

    BETA

    Organise items into folders and mark favourites.

    iPhone

  • Password and passphrase generator

    BETA

    Generates random passwords or word-based passphrases with the options you choose.

    iPhone

  • Two-factor codes

    READY

    Stores authenticator seeds and shows the current six-digit code.

    Linux · iPhone (Beta) · Chromium browsers (Beta)

  • Passkeys

    BETA

    Stores passkeys and signs you in with them on iPhone.

    iPhone

  • SSH keys

    READY

    Stores SSH keys as vault items.

    Linux

  • Vault health

    BETA

    Flags reused and weak passwords. The check runs on your iPhone.

    iPhone

  • Import

    READY

    Import logins, notes, cards, identities and passkeys from one other password manager's JSON export. Other export formats are not supported yet.

    Linux

  • Encrypted export

    READY

    Write the whole vault to an encrypted file, or to an encrypted .kdbx database you can open in other tools.

    Linux

Autofill and browser

  • Browser autofill

    BETA

    Fills a login on the domain it was saved for, subdomains included. It takes the last two parts of the address as the domain (three for some endings, such as .co.uk), so two sites on github.io count as one.

    Chromium browsers

  • In-page suggestions

    BETA

    A menu beside the username and password fields offers the matching logins.

    Chromium browsers

  • Save new logins

    BETA

    Offers to save a login after you sign in somewhere new.

    Chromium browsers

  • Two-factor code fill

    BETA

    Fills the current two-factor code into the page's code field.

    Chromium browsers

  • Browser extension sign-in

    BETA

    The browser extension signs in with your email and master password and syncs your vault, with no other software to install.

    Chromium browsers

Phones

  • iPhone app

    BETA

    Browse, search and use your vault on iPhone.

    iPhone

  • iPhone AutoFill

    BETA

    Fills passwords, one-time codes and passkeys in apps and Safari.

    iPhone

  • Face ID and Touch ID

    BETA

    Unlock with Face ID or Touch ID. Changing the enrolled biometrics requires the master password again.

    iPhone

  • Add and edit on iPhone

    BETA

    Create and edit logins on the phone. Changes sync to your other devices.

    iPhone

Devices and sync

  • Sync across devices

    BETA

    Changes made on one device appear on your others automatically.

    iPhone · Chromium browsers · Linux

  • Simultaneous edits are merged

    BETA

    Edits made on two devices at the same time are merged item by item. A true conflict keeps both copies.

    Linux · iPhone · Chromium browsers

  • Device management

    BETA

    See your signed-in devices and sign any of them out.

    Linux

Accounts and recovery

  • Email and master password

    BETA

    Create an account and sign in on each device with your email and master password. No QR code.

    Linux · iPhone · Chromium browsers

  • Recovery kit

    BETA

    A recovery key is shown once at sign-up. With it you can set a new master password if you forget yours. We can't open your vault for you without one.

    Linux · iPhone · Chromium browsers

  • Recovery waiting period

    BETA

    A recovery waits 72 hours before it can complete. Until then, the iPhone app shows it in Settings and the command line shows it in account status, and either can cancel it.

    Linux · iPhone

  • Change master password

    BETA

    Changing the master password signs out every other device.

    Linux

AI assistants and developers

  • MCP server

    READY

    Gives AI assistants tools to find, use and add credentials, with the secret kept out of each tool's reply.

    Linux

  • Single-use handles

    READY

    An assistant gets a one-time handle, not the password. It expires after 60 seconds by default.

    Linux

  • Materialise to file

    READY

    A secret is written to a temporary file with owner-only permissions, and deleted when it expires. It isn't put into the conversation, a command line or our logs.

    Linux

  • Redacted reads

    READY

    Listing and viewing items shows passwords and other secret fields as [PROTECTED] instead of the value. Names, usernames, site addresses and notes that don't look like secrets are shown.

    Linux

  • Leak contract

    READY

    A test sweeps a marker secret through each command, tool, log and error, and fails the build if any one of them returns it. It checks each tool on its own.

    Linux

  • Fill browser fields for an assistant

    READY

    Types a secret straight into a field in a browser you opened for remote debugging, so the value stays out of the conversation. It doesn't yet check that the page is the site the login was saved for.

    Linux

  • Two-factor codes for assistants

    READY

    An assistant can have a current two-factor code typed into a page without the code or the seed being returned to it.

    Linux

  • Ask the owner for a secret

    READY

    An assistant can ask you for a credential through a one-time form. The value goes straight into the vault.

    Linux

  • Audit trail

    READY

    Keeps an append-only, value-free record of login activity.

    Linux

  • Command line

    READY

    Create, list, unlock and sync a vault from the terminal. Secrets are read from files, never from arguments.

    Linux

  • Desktop app for Linux

    READY

    A tray app to unlock, search, add and edit items in a local vault on your computer. It does not open an account vault yet.

    Linux

  • Agent vaults

    BETA

    Each assistant works from its own separate vault with its own key, which can't open your personal vault.

    Linux

  • Scoped agent credentials

    BETA

    Issue an assistant a credential limited to named agent vaults, and revoke it at any time.

    Linux

Not yet: Android, family and team sharing, Firefox and Safari. See the gaps

05 · Straight answers

The questions we’d ask too.

Letting software near your passwords should make you suspicious. Here’s what we protect against and what we don’t. What isn’t built yet is listed on the Security page.

Protects against

  • Passwords landing in chat history, logs or the command line during normal use
  • An assistant with an agent vault opening your personal vault: its key opens its own vault, not yours
  • The server, or anyone who breaks into it, reading your vault
  • A tampered vault: your devices check the signature on every download

Doesn’t protect against

  • An assistant you’ve connected that sets out to read or misuse what’s in the vault you gave it
  • Anything running as your user on your computer, including an assistant with shell access
  • A web page that tricks your assistant into typing a password into the wrong site
  • A weak master password, if someone captures your sign-in key
  • A brand-new device being shown an old copy of your vault
Why would I let an AI anywhere near my passwords?

You don’t have to: the vault works without one. If you do connect one, give it its own agent vault with only the logins it needs. Its key can’t open your personal vault, and you can revoke it at any time. Treat a connected assistant as able to see everything in the vault you give it.

Can my assistant read the passwords it uses?

In normal use it gets a single-use handle, a typed field or a short-lived private file, so the password stays out of the chat. That is not a promise against an assistant that sets out to dig for it.

Today a connected assistant can recover a password by chaining our own tools, and one with shell access can read the file we write for it. We’re closing the tool route before we invite testers. Until then, scope its vault to what you’d be fine with it seeing.

What if a web page tricks my assistant?

Today there’s no approval step when an assistant uses a login. Our browser typing tools don’t yet check that the page belongs to the site the login was saved for, and an assistant can change an item’s saved sites. So a hijacked assistant could type a password into the wrong site.

Before we invite testers, assistant fills will be limited to the sites a login was saved for, and changing those sites from an assistant will need your approval. Until then, don’t connect an assistant that browses untrusted pages to a vault holding anything important.

Is it safe to unlock the vault on a computer where AI agents run?

Not yet. On Linux, atlas-vault unlock leaves a key in a file in your home folder until you run atlas-vault lock. Anything running as your user can read it, including an assistant with shell access.

If you run our assistant server as an always-on local service, it accepts any connection from your computer without a token. We’re adding an expiry to that file and a required token before we invite testers. Until then, run assistants as a separate user or in a sandbox, and lock the vault when you’re done.

What does the company running my assistant learn?

To find the right login, an assistant sees item names, usernames, website addresses, identity details and notes that don’t look like secrets. So the company running your assistant learns which services you use.

Our note filter misses some secrets, such as PINs, seed phrases and backup codes, so keep those out of notes on items an assistant can reach. Some replies also include a short hash and the length of a value, which someone holding the chat could use to check guesses at a weak password. We’re hiding notes from assistants and switching to a keyed fingerprint before we invite testers.

Does my master password leave my device?

No. Your device stretches it with Argon2id, at least 256 MiB of memory and 3 passes, and refuses weaker settings even if a server asks for them. It then sends a separate sign-in key derived from it, which can’t decrypt anything. The server stores a hash of that key.

Someone who captured the sign-in key, including Cloudflare, which carries the connection, could try to guess a weak master password offline. Today they could also use it to change your account password or recovery key and lock you out of sync, though not to read your vault. Use a long master password that you use nowhere else.

Who runs the server, and what can it see?

We do, during the beta, on a machine we operate in Perth, behind a Cloudflare tunnel. It’s a separate service with its own data and keys, but not a dedicated host, and its backups are on the same machine for now.

It sees your email, your devices, how many items you have, their encrypted sizes, when they change and your IP address when you connect. It can’t decrypt your vault, but it could withhold or delete it, so keep an encrypted export.

Could the server roll my vault back to an old version?

Partly. On a normal sync, each device remembers the newest version it has seen and refuses an older copy, on Linux, iPhone and the browser extension. A new or reinstalled device has nothing to compare against, and our own review found one Linux sync path that could accept an older signed copy. We’re fixing that path before we invite testers.

Has anyone independent reviewed this? Who wrote it?

Not yet. Atlas Vault is about three months old, and much of it was written with AI coding tools. A change merges when the required automated checks pass, without a second person approving it. The encryption comes from libsodium and the Python cryptography library, not primitives of our own, and every change runs our leak test before it can merge. We’ll commission an independent security review before general availability.

What happens to the email I give the waitlist?

It’s stored in a Supabase database in Singapore with the use you picked, your consent and the time. Cloudflare Turnstile checks you’re a person once you start filling in the form (typing, clicking into the email field or choosing an option, not reading or scrolling past it), and we get a one-line Discord notice with a masked address. To be removed, email contact@atlas-ai.au and we’ll delete your entry by hand. The full list of services is on the Privacy page.

06 · Compared

Compared with other password managers.

Where they are ahead, we say so.

FeatureAtlas VaultOther password managers
End-to-end encrypted vaultAvailableStandard
Zero-knowledgeBetaStandard
PasskeysBetaStandard
Single-use handlesAvailableSome offer it
Agent vaultsBetaSome offer it
Android appNot yetStandard
Family and team sharingNot yetStandard

Sources, checked 2026-10. Each row in the “Other password managers” column rests on at least two published pages from other password managers or the press (30 pages in all). We don’t name other products on this site.

See the full comparison

Private beta

Want in? Leave your email.

We’re letting people in a few at a time. We’ll email you when there’s room, and only about the beta.

What will you use it for? Optional