Encrypted before it leaves your device
Every password is sealed on your device first — our servers are never given a plaintext password to protect or lose.
How it works
No account, no server, and no support engineer ever sees your real passwords. Here's what happens behind the scenes for every core PassKub flow — and why it's built so a data leak can't expose what's inside your vault.
Your vault
When you save a password, PassKub turns it into unreadable ciphertext right there on your device, using a key only your keypass can unlock. Nothing is written to disk until it's already locked.
PassKub never stores your keypass, so nobody — including us — can unlock your vault without it.
Sync Vault
Premium sync copies your vault between your own devices through our servers, but it never unlocks along the way. Our servers only ever handle a sealed box they can't open.
Even if our servers were ever breached, there's nothing readable to steal — only sealed ciphertext.
Team Sync Vault · Business
A Business team vault has a single shared vault key, but that key is individually sealed for each teammate using their own personal key. Our servers store the sealed copies only — never a usable key.
Remove someone from the team and their key stops opening anything new — there's no shared master password to leak.
Family Sync Vault
Family Sync Vault uses the exact same sealed-key model as Team Sync Vault — every family member gets their own personal key to the shared vault, so passwords can be shared at home without a single point of failure.
One shared vault, every member's own key — no single password everyone has to protect.
Local Quick Fill
Local Quick Fill types a saved password into another app or browser on the very same device. There's no network involved at all, so there's nothing in transit to intercept.
No internet connection is used or required — the credential never leaves your computer.
Request Quick Fill
Need a password on a second device without opening your whole vault there? Request Quick Fill sends just that one credential, end-to-end encrypted, and it's approved by matching a shape — never by typing anything a relay could read.
The relay only ever sees a sealed, one-time envelope it cannot open — and it expires within minutes even if unused.
Why you can trust this
Every password is sealed on your device first — our servers are never given a plaintext password to protect or lose.
We store ciphertext, sealed keys, and public keys only — there's no plaintext copy anywhere in our systems, even for support.
Quick Fill requests and sync hand-offs are one-time and short-lived — expired data is deleted, not kept "just in case."
Your keypass is never sent to us and never stored anywhere. That's the trade-off of true zero-knowledge security — even we can't recover it for you.