Generate. Encrypt.
Own your keys.
PassCipher generates highly secure passwords, SSH keys and other secrets, then locks them in a vault encrypted on your machine. No cloud. No account. No telemetry.
One-time €5 €1.49. No subscription, ever. Works fully offline after a one-time activation.
PassCipher generates secrets this strong, then encrypts them into a local vault only you can open.
Built to keep secrets secret
Generate strong material and store it locally, encrypted, and out of sight.
Every key type
Passwords, passphrases, usernames, SSH keys (Ed25519, RSA, ECDSA), PGP keypairs, AES symmetric keys and API tokens - all from one dropdown - plus per-site email aliases for your logins.
Encrypted local vault
Everything is sealed with AES-256-GCM into a single vault file only PassCipher can open. No cloud, no account, no sync.
Hidden by default
Secrets never sit on screen. Reveal one at a time, or copy to the clipboard - which wipes itself after a few seconds.
Optional password and 2FA
Add an Argon2id master password, a TOTP authenticator code, both, or neither. Recovery codes keep you from being locked out.
Screen-capture resistant
The window is hidden from screenshots, the Snipping Tool and screen-share on Windows.
Tag your keys
SSH and PGP keys carry a comment or user ID, so the right key is easy to recognise in the vault later.
How PassCipher compares
Built for local, individual use. Here is where it differs from the managers people switch from.
| PassCipher | 1Password | Bitwarden | KeePass | |
|---|---|---|---|---|
| Works fully offline, no cloud sync | ✓ | – | ~ | ✓ |
| No account to sign up for | ✓ | – | – | ✓ |
| No telemetry or analytics | ✓ | – | ~ | ✓ |
| Generates SSH, PGP and AES keys plus API tokens | ✓ | ~ | – | – |
| Username and email-alias generation | ✓ | – | ~ | – |
| Master password is optional | ✓ | – | – | – |
| Blocks screenshots and screen-share | ✓ | – | – | – |
| Built-in encrypted backup export | ✓ | ~ | ~ | ✓ |
Reflects each product's common configuration in 2026. The others do plenty PassCipher does not - team sharing, browser autofill, mobile sync, breach monitoring. PassCipher trades those for a local-only vault you fully control. (~ means partial or optional.)
Honest about the security model
Strong cryptography, and a straight answer about what it does and does not protect.
Your secret
A password or key, generated locally with your OS cryptographic RNG.
Argon2id key
Your master password is stretched into a key with a memory-hard KDF. No password? The OS keystore holds it.
AES-256-GCM vault
The secret is sealed into a single encrypted file on your disk. Only you can open it.
Per-item sealing
Each secret value is individually encrypted, so revealing one entry decrypts only that entry. Nothing is held in plaintext longer than it needs to be.
You hold the keys
No PassCipher account and nothing leaves your machine. Lose your password and your recovery codes and the vault cannot be opened - that is the point of real encryption.
Spelled out, not spun
The threat model is documented in the app and below. We would rather tell you the limits than oversell.
Known limits
- Screen-capture blocking is best effort: it stops normal screenshots and screen-share on Windows, but not a phone camera, a kernel-level capture, or malware already running as you. There is no Linux equivalent.
- The clipboard can still leak through Windows clipboard history, cloud clipboard sync, or third-party managers. Auto-clear shortens the window but does not remove it - disable clipboard history for the most sensitive copies.
- With no master password, the vault is only as strong as your Windows account. A master password adds a secret the operating system does not already hold; 2FA on its own gates the app but does not encrypt a copied file.
Questions, answered
Yes. There is no PassCipher server and no account. Your vault is a single encrypted file in your app data folder. Nothing is ever uploaded. The app makes no network calls except an optional update check and, if you switch on 'fetch site icons', pulling those icons from the sites you save (off by default).
Nine generator types plus email aliases: random passwords, word passphrases, usernames, SSH keys (Ed25519, RSA 2048/3072/4096, ECDSA P-256/P-384/P-521), PGP/GPG keypairs (curve25519 or RSA), raw AES symmetric keys (128/192/256-bit, hex/base64), and high-entropy API tokens. The accounts view also generates per-site email aliases ([email protected] plus-addressing, or [email protected] via a catch-all domain).
If you set one, save the recovery codes shown at setup - any one of them can unlock the vault. If you lose both the password and every recovery code, the vault cannot be opened. That is real encryption working as intended, not a bug.
Not built in - PassCipher is deliberately local. You can export a password-encrypted backup (.pcvault) and move it yourself, then import it on another machine.
Those are excellent cloud managers with sharing, autofill and mobile apps. PassCipher is the opposite trade: no cloud, no account, no telemetry, plus nine generator types (passwords, passphrases, usernames, SSH, PGP and AES keys, API tokens) and an optional (not mandatory) master password. It is for individuals who want a local vault they fully control.
KeePass is local too, but PassCipher adds SSH, PGP and AES key generation, API tokens, email aliases, screen-capture blocking, optional 2FA, and a modern dark UI. Windows Credential Manager is tied to your account, not portable, and has no key generation or master password.
No. PassCipher is proprietary, closed-source software by Wrenchy Productions. It is still fully local: your vault never leaves your machine, there is no account and no telemetry, the threat model and its limits are documented openly on this site, and it is a one-time purchase - so there is no business model built on your data.
Windows (installer), Linux (AppImage and .deb) and Android (APK). Your vault moves between them via an encrypted backup export. SSH key generation is desktop-only (Windows and Linux); every other generator works on Android too.
Screen-capture blocking does not stop a phone camera or malware already running as you, and has no Linux equivalent. The clipboard can still leak via Windows clipboard history. With no master password set, the vault is only as strong as your Windows account.
PassCipher is a one-time purchase: EUR 1.49 for all platforms (Windows, Linux, Android), shown in your local currency at checkout. No subscription and no upsell. After a one-time activation it works fully offline, and one purchase covers one device per platform.
Own your secrets
One-time €5 €1.49 for Windows, Linux and Android. No subscription, ever. Buy once, paste your key, and your vault is encrypted before anything touches disk. No account. No cloud.
Windows installer (.exe), Linux AppImage, and an Android APK. Need the Debian package? Download the .deb. The builds are unsigned for now, so Windows SmartScreen may warn of an unknown publisher and Android will ask you to allow installing the APK.