How Keyhold protects your data
Plainly, including what it cannot protect against. The source code is open on GitHub, so all of this can be checked.
One encrypted file
Everything — logins, two-factor keys, notes and files — lives in one file, encrypted with AES-256-GCM under a random 256-bit vault key. The file is useless without that key: a backup copy, a lost disk or the copy in your Google Drive shows nothing but random bytes.
Where the vault key is kept
- On Windows the vault key is sealed with DPAPI, bound to your Windows account. Keyhold opens without asking for a password once you are signed in to Windows — a deliberate choice, so it is simple enough for anyone to use every day. If you want more, turn on Windows Hello: Keyhold then asks for your face, fingerprint or Windows PIN when it opens, and locks after 5 minutes without use.
- On Android it is sealed by a key held in the phone’s Android Keystore, which never leaves the phone’s secure hardware. With the fingerprint lock on, Keyhold opens only after your fingerprint (or the phone’s PIN), and its screens cannot be captured in screenshots.
- The master password wraps the same vault key a second time, with Argon2id (64 MiB of memory, 3 passes), which makes guessing slow and expensive. Every vault has one, set when the vault is made. It is needed where DPAPI or the Keystore do not apply: another device opening the vault, and the browser extension opening it from Google Drive on a computer without the Keyhold app. The master password itself is never stored anywhere.
- The recovery key — 160 random bits — wraps the vault key a third time, for a forgotten master password. Keyhold prints two of its three rows on a recovery sheet; the third is copied onto it by hand and checked, so the printout alone opens nothing.
Fingerprint and Windows Hello for single entries
Any login or code can be marked to ask for its owner: it is then filled in, typed or copied only after a fingerprint on the phone or Windows Hello on the computer. A device with neither asks for the master password instead. The fingerprint and the face never reach Keyhold — the phone and Windows check them and only say yes or no.
No server
There is no Keyhold server and no account. Sync goes through your own Google Drive, where Keyhold can see only its own “Keyhold” folder, and the file arrives there already encrypted. The author of Keyhold never receives your data, your password or your Google access.
The browser extension
- A web page never gets more than the one login you pick for it, and only a login kept for exactly that site; the rest of the vault stays out of its reach. A page cannot hide Keyhold’s list to make you pick from it unseen.
- With the Keyhold app on the same computer, the extension talks only to it, at
127.0.0.1, and every call carries the pairing token shown in the app. - Without the app, the extension downloads the encrypted vault from your Drive and opens it with your master password. The vault key then stays in the browser’s memory until you lock it, close the browser or leave it for 30 minutes — the same way other password managers’ extensions work.
- A login you type in is held only in memory for two minutes until you confirm it; nothing is written before that.
What Keyhold cannot protect against
- Someone using your unlocked Windows account can open Keyhold unless you turned on Windows Hello, just as they can open your browser with its saved passwords. Lock your computer when you leave it.
- Malware running on your computer or phone can read what you can read. No password manager can prevent that; keep the system updated.
- A forgotten master password and a lost recovery key cannot be recovered by anyone — there is no back door. Devices that already have the vault keep working; another device cannot open it without one of the two.