Keyhold

How Keyhold protects your data

Plainly, including what it cannot protect against. The source code is open on GitHub, so all of this can be checked.

One encrypted file

Everything — logins, two-factor keys, notes and files — lives in one file, encrypted with AES-256-GCM under a random 256-bit vault key. The file is useless without that key: a backup copy, a lost disk or the copy in your Google Drive shows nothing but random bytes.

Where the vault key is kept

Fingerprint and Windows Hello for single entries

Any login or code can be marked to ask for its owner: it is then filled in, typed or copied only after a fingerprint on the phone or Windows Hello on the computer. A device with neither asks for the master password instead. The fingerprint and the face never reach Keyhold — the phone and Windows check them and only say yes or no.

No server

There is no Keyhold server and no account. Sync goes through your own Google Drive, where Keyhold can see only its own “Keyhold” folder, and the file arrives there already encrypted. The author of Keyhold never receives your data, your password or your Google access.

The browser extension

What Keyhold cannot protect against