Skip to main content
Dark Pools product · End-to-end encrypted password manager

Password management where vault contents reach the server only as ciphertext

KeyCare Pass stores passwords, passkeys, payment cards, identities, secure notes and SSH keys in a vault that is encrypted on the user’s device before anything is synced. Organizations share credentials through collections and groups, enforce two-step login and master password rules by policy, and keep an event log of who viewed, changed or shared what. Run it on the hosted service in the European Union or on your own Docker host.

Visit keycarepass.com
YOUR DEVICESERVERDECRYPTED ONLY BY01Master passwordNever leaves the device02Master keyPBKDF2-SHA256 or Argon2id03Account key512-bit, stored wrapped04Encrypt every fieldAES-256 with HMAC-SHA256Ciphertext onlyStores and syncsencrypted itemsYour other devicesDecrypt locallyOrganization membersKeys sent with RSA-OAEPSend linksKey in the # fragmentThe server never receives the master password or any key derivedfrom it, so it cannot read vault contents.
Overview

What KeyCare Pass does

KeyCare Pass gives each person a private vault and gives organizations shared collections on top of it. The master password never leaves the device: it is stretched into a master key with PBKDF2-SHA256 or Argon2id, and that key protects a random account key which encrypts every item field, names included, with AES-256 and authenticates it with HMAC-SHA256. The service stores and synchronizes ciphertext, which is why it cannot reset a forgotten master password and why a breach of its servers would not expose vault contents.

For teams, the organization is the unit of control. Owners and admins invite members, confirm them after comparing a fingerprint phrase derived from the member’s public key, assign them to groups and collections, and revoke or remove them when they leave. Business and Enterprise plans add policies such as required two-step login, master password rules, generator rules and single-organization membership, plus account recovery for enrolled members. Admins manage access to shared items and are not given the keys to anyone’s personal vault.

KeyCare Pass is part of the GovPAM product family, and it is open source: the apps are licensed GPL-3.0 and the server AGPL-3.0, and a source archive is published for each release that runs the hosted service. A security team can check the published whitepaper against the code instead of taking the design on trust. The product was previously called KeyGuard Password, and accounts, vaults and the browser extension carried over unchanged.

Capabilities

Built in, not bolted on

Encrypted vault and autofill

One vault holds every credential type a person or team needs, encrypted field by field before it leaves the device.

  • Logins, passkeys, payment cards, identities, secure notes and SSH keys
  • Autofill from the page, the toolbar or the right-click menu, and an offer to save new and changed logins at sign-in
  • HTTP basic-authentication prompts filled from the vault
  • Encrypted file attachments on any item, up to 1 GB per person
  • Import from other password managers and browsers, and export at any time

Generator and vault health

Reports show where a vault is weak, and the generator replaces what they find without anyone having to invent or remember a password.

  • Random passwords, passphrases and usernames on demand, with generator rules set by policy
  • Reports for weak, reused and exposed passwords, unsecured websites and missing two-step login
  • Exposed-password checks by k-anonymity: only the first five characters of a SHA-1 hash leave the device
  • Organization reports covering the passwords held in shared collections

Passkeys and built-in authenticator

Passkeys and one-time codes live in the same encrypted vault as the logins they protect, and a passkey can also sign in to KeyCare Pass itself.

  • Website passkeys saved in the vault and used to sign in
  • Passkey sign-in to the web vault; where the browser supports the WebAuthn PRF extension, the same passkey also decrypts the vault
  • Six-digit TOTP codes stored next to their logins and refreshed every 30 seconds

Account safeguards

Two-step login, sign-in alerts and emergency access protect the account itself, separately from the encryption that protects its contents.

  • Two-step login by authenticator app, FIDO2 security key, passkey, email code or Duo
  • Sign-in history for the last 90 days, and an email when a sign-in comes from an unfamiliar IP address
  • Email confirmation of new devices for accounts without two-step login
  • Emergency access: a trusted contact can view or take over the vault after a waiting period, unless the owner rejects the request

Sharing, collections and Send

Shared credentials are organized by team, client or system, and each member sees only the collections they have been granted.

  • Collections with five permission levels, from view with passwords hidden to full manage rights
  • Groups that give a whole team access to its collections in one step
  • Send: text or a file shared by an encrypted, expiring link whose key never reaches the server, with an optional password

Admin console and policies

Owners and admins run the organization from one console with sections for collections, members, groups, reporting, billing and settings.

  • Invite, confirm after comparing a fingerprint phrase, revoke and remove members, with bulk confirmation
  • Policies for required two-step login, master password rules, generator rules and single-organization membership
  • Policies to remove Send, the card item type or PIN access, enforce centralized ownership and set default URI matching
  • Account recovery administration for enrolled members on Business and Enterprise
  • Custom admin roles on Enterprise that limit each administrator to the rights they need

Event logs and public API

Organization activity is recorded with a time and an IP address and can be pulled into the tools your team already monitors.

  • Item views and changes, collection and group changes, invitations, policy edits and sign-ins
  • Public API to manage members, groups, collections and policies and to read event logs
  • Organization vault export, and import of shared credentials into collections

MSP panel

Managed service providers run every client organization from one place, without a separate seat in each.

  • Every client listed with plan, seats in use, payer and status
  • One click into a client’s Admin Console to manage its members, collections and settings
  • Client organization keys shared with the MSP’s key in the browser, so the service never sees them
  • MSP event log of clients and staff added or removed, and of staff opening a client vault
  • One itemized monthly bill for the clients the MSP pays for
How it works

KeyCare Pass, step by step

  1. 01Derive keysThe master password is stretched on the device into a 256-bit master key with PBKDF2-SHA256 or Argon2id, using the email address as salt. Only a further hash is sent to sign in, and the server hashes it again before storing it.
  2. 02Encrypt on deviceA random account key encrypts every field of every item, names included, with AES-256 and a fresh IV, and authenticates it with HMAC-SHA256. Attachments get their own per-file key.
  3. 03Sync ciphertextThe server stores and synchronizes encrypted items, the wrapped account key and public keys. It never receives the master password or any key derived from it.
  4. 04Confirm membersWhen an admin confirms a new member, the organization key is encrypted to that member’s RSA-2048 public key with RSA-OAEP. Both sides can compare a fingerprint phrase first to detect key substitution.
  5. 05Share collectionsCollection permissions decide which shared items each member can see, fill and change. Members never receive another member’s account key.
  6. 06Log and reviewEvent logs, sign-in history and vault health reports show who did what, from where, and which passwords need replacing. The public API carries the logs into your own tooling.
Security architecture

How your secrets are protected

  • The master password never leaves the device. It is stretched into a 256-bit master key with PBKDF2-SHA256 (600,000 iterations by default, adjustable to 2,000,000) or Argon2id (six iterations, 32 MiB and parallelism of four by default, adjustable to 1,024 MiB), with the email address as salt.
  • A random 512-bit account key, stored on the server only in wrapped form, encrypts every item field with AES-256-CBC and a random IV, and authenticates each item with HMAC-SHA256 so tampering is caught before decryption.
  • Changing the master password re-wraps a single key. If the master password may have been exposed, rotating the account key re-encrypts the whole vault in one step.
  • Each account holds an RSA-2048 key pair. Organization keys reach members only after an admin confirms them, encrypted to the member’s public key with RSA-OAEP, and a fingerprint phrase lets both sides detect key substitution.
  • To sign in, the client sends a hash of the master key, which the server passes through a further 100,000 PBKDF2 iterations before storing or comparing it.
  • Send keys travel only in the link fragment after the # sign, so the server holds Send contents it cannot decrypt.
  • The service sees account metadata such as email, devices, sign-in times, IP addresses, memberships and event logs. It never sees the master password, item contents, item and folder names, attachments or Send contents.
Deployment & editions

Run it the way your organization works

  • Hosted service: the web vault at vault.keycarepass.com, running on servers in the European Union with a PostgreSQL database and TLS on all traffic
  • Self-hosted: the full server on your own Docker host with PostgreSQL 16 behind your reverse proxy, licensed by installation ID with no outbound call to the vendor or a billing service
  • Personal editions: Premium for one person, and Families for up to six people with a shared household collection alongside each private vault
  • Business editions: Teams for shared collections, event logs and the public API; Business adds policies and account recovery; Enterprise adds custom admin roles. Teams and Enterprise include a 14-day trial with no card required
  • Available now: the web vault in any modern browser and a browser extension for Chrome, Edge, Brave, Opera and Vivaldi. Desktop apps for Windows, macOS and Linux, mobile apps for iOS and Android, and Firefox and Safari extensions are listed as coming soon
  • Managed rollout: force-install the extension through the ExtensionInstallForcelist policy in Google Admin, Group Policy or an MDM, or use the signed self-hosted extension package on networks that block the Chrome Web Store
Who it is for

Teams that rely on it

IT and security teams

Administrator and service logins organized by system in collections, with permissions that let a member use a password without seeing it. A policy can require two-step login across the organization, and the event log shows who viewed or changed an item and from which IP address.

Regulated and public-sector organizations

Self-host on your own Docker host so the encrypted vault, files and logs stay on infrastructure you control, under a license that needs no outbound connection. Open source code and a published whitepaper give a security review something concrete to test.

Managed service providers

Run every client organization from one MSP panel, open a client’s Admin Console in one click, and work inside client organizations without being added to each. The MSP event log records when staff open a client vault, and paid clients roll up into one itemized monthly bill.

Individuals and families

Premium covers one person and Families covers up to six, each with a private vault and a shared household collection, plus emergency access for a trusted contact and a built-in authenticator for two-step codes.

Frameworks

Controls that support your obligations

KeyCare Pass provides controls and evidence that help organizations meet these frameworks. Certification of your environment remains with your assessor.

  • NIS2 Article 21(2): cryptography (h), access control (i), multi-factor authentication (j) and basic cyber hygiene (g), through on-device encryption, collection permissions, a policy requiring two-step login and vault health reports
  • ISO/IEC 27001:2022 Annex A: access control and identity management (5.15 to 5.18), privileged access rights (8.2), secure authentication (8.5), logging (8.15) and use of cryptography (8.24)
  • NIST SP 800-63B and CSF 2.0: long generated secrets, checks against compromised passwords and multi-factor authentication, mapped to the PR.AA, PR.DS and DE.CM outcomes
  • SOC 2: the logical access and monitoring criteria, supported by roles, collection permissions and event logs with IP addresses
  • POPIA Section 19: security safeguards for personal information, including encrypted storage of credentials and logged access to shared items
FAQ

KeyCare Pass questions

Get started

Take the next step

See KeyCare Pass in your environment, with a walkthrough tailored to your teams and systems.

All cybersecurity