Local-first secrets vault

Generate. Encrypt.
Own your keys.

PassCipher generates highly secure passwords, SSH keys and other secrets, then locks them in a vault encrypted on your machine. No cloud. No account. No telemetry.

One-time €5 €1.49. No subscription, ever. Works fully offline after a one-time activation.

Already purchased? Download
Try the generatorruns in your browser
Excellent128 bits · longer than the universe has existed to crack
Length20

PassCipher generates secrets this strong, then encrypts them into a local vault only you can open.

Built to keep secrets secret

Generate strong material and store it locally, encrypted, and out of sight.

Every key type

Passwords, passphrases, usernames, SSH keys (Ed25519, RSA, ECDSA), PGP keypairs, AES symmetric keys and API tokens - all from one dropdown - plus per-site email aliases for your logins.

Encrypted local vault

Everything is sealed with AES-256-GCM into a single vault file only PassCipher can open. No cloud, no account, no sync.

Hidden by default

Secrets never sit on screen. Reveal one at a time, or copy to the clipboard - which wipes itself after a few seconds.

Optional password and 2FA

Add an Argon2id master password, a TOTP authenticator code, both, or neither. Recovery codes keep you from being locked out.

Screen-capture resistant

The window is hidden from screenshots, the Snipping Tool and screen-share on Windows.

Tag your keys

SSH and PGP keys carry a comment or user ID, so the right key is easy to recognise in the vault later.

How PassCipher compares

Built for local, individual use. Here is where it differs from the managers people switch from.

PassCipher1PasswordBitwardenKeePass
Works fully offline, no cloud sync~
No account to sign up for
No telemetry or analytics~
Generates SSH, PGP and AES keys plus API tokens~
Username and email-alias generation~
Master password is optional
Blocks screenshots and screen-share
Built-in encrypted backup export~~

Reflects each product's common configuration in 2026. The others do plenty PassCipher does not - team sharing, browser autofill, mobile sync, breach monitoring. PassCipher trades those for a local-only vault you fully control. (~ means partial or optional.)

Honest about the security model

Strong cryptography, and a straight answer about what it does and does not protect.

01

Your secret

A password or key, generated locally with your OS cryptographic RNG.

02

Argon2id key

Your master password is stretched into a key with a memory-hard KDF. No password? The OS keystore holds it.

03

AES-256-GCM vault

The secret is sealed into a single encrypted file on your disk. Only you can open it.

Per-item sealing

Each secret value is individually encrypted, so revealing one entry decrypts only that entry. Nothing is held in plaintext longer than it needs to be.

You hold the keys

No PassCipher account and nothing leaves your machine. Lose your password and your recovery codes and the vault cannot be opened - that is the point of real encryption.

Spelled out, not spun

The threat model is documented in the app and below. We would rather tell you the limits than oversell.

Known limits

  • Screen-capture blocking is best effort: it stops normal screenshots and screen-share on Windows, but not a phone camera, a kernel-level capture, or malware already running as you. There is no Linux equivalent.
  • The clipboard can still leak through Windows clipboard history, cloud clipboard sync, or third-party managers. Auto-clear shortens the window but does not remove it - disable clipboard history for the most sensitive copies.
  • With no master password, the vault is only as strong as your Windows account. A master password adds a secret the operating system does not already hold; 2FA on its own gates the app but does not encrypt a copied file.

Questions, answered

Yes. There is no PassCipher server and no account. Your vault is a single encrypted file in your app data folder. Nothing is ever uploaded. The app makes no network calls except an optional update check and, if you switch on 'fetch site icons', pulling those icons from the sites you save (off by default).

Nine generator types plus email aliases: random passwords, word passphrases, usernames, SSH keys (Ed25519, RSA 2048/3072/4096, ECDSA P-256/P-384/P-521), PGP/GPG keypairs (curve25519 or RSA), raw AES symmetric keys (128/192/256-bit, hex/base64), and high-entropy API tokens. The accounts view also generates per-site email aliases ([email protected] plus-addressing, or [email protected] via a catch-all domain).

If you set one, save the recovery codes shown at setup - any one of them can unlock the vault. If you lose both the password and every recovery code, the vault cannot be opened. That is real encryption working as intended, not a bug.

Not built in - PassCipher is deliberately local. You can export a password-encrypted backup (.pcvault) and move it yourself, then import it on another machine.

Those are excellent cloud managers with sharing, autofill and mobile apps. PassCipher is the opposite trade: no cloud, no account, no telemetry, plus nine generator types (passwords, passphrases, usernames, SSH, PGP and AES keys, API tokens) and an optional (not mandatory) master password. It is for individuals who want a local vault they fully control.

KeePass is local too, but PassCipher adds SSH, PGP and AES key generation, API tokens, email aliases, screen-capture blocking, optional 2FA, and a modern dark UI. Windows Credential Manager is tied to your account, not portable, and has no key generation or master password.

No. PassCipher is proprietary, closed-source software by Wrenchy Productions. It is still fully local: your vault never leaves your machine, there is no account and no telemetry, the threat model and its limits are documented openly on this site, and it is a one-time purchase - so there is no business model built on your data.

Windows (installer), Linux (AppImage and .deb) and Android (APK). Your vault moves between them via an encrypted backup export. SSH key generation is desktop-only (Windows and Linux); every other generator works on Android too.

Screen-capture blocking does not stop a phone camera or malware already running as you, and has no Linux equivalent. The clipboard can still leak via Windows clipboard history. With no master password set, the vault is only as strong as your Windows account.

PassCipher is a one-time purchase: EUR 1.49 for all platforms (Windows, Linux, Android), shown in your local currency at checkout. No subscription and no upsell. After a one-time activation it works fully offline, and one purchase covers one device per platform.

Own your secrets

One-time €5 €1.49 for Windows, Linux and Android. No subscription, ever. Buy once, paste your key, and your vault is encrypted before anything touches disk. No account. No cloud.

Already purchased? Download

Windows installer (.exe), Linux AppImage, and an Android APK. Need the Debian package? Download the .deb. The builds are unsigned for now, so Windows SmartScreen may warn of an unknown publisher and Android will ask you to allow installing the APK.