Password Manager
Logins, cards and notes, behind the same PIN as everything else.
It is opt-in
Generator
Builds passwords locally. Nothing generated is transmitted, logged, or reused across entries.
Breach check
Tells you whether a password appears in known breach corpora, without your password ever leaving the device in a readable form.
Expiry & audit
Flags entries that are stale, weak, or reused, so a vault that has grown over years does not quietly rot.
CSV import
Brings entries in from another manager, parsed on-device. Logins that look like card numbers are reclassified rather than silently stored as passwords.
One PIN, one key
The vault is not a separate product with its own password. It is encrypted with the same PIN-derived key as your financial data, held in memory only and never written to disk. That is why the vault requires a PIN even when app lock is otherwise relaxed: without the key there is nothing to decrypt, so the surface cannot be shown at all.
A forgotten PIN is not recoverable by us
