Dark Pools product · End-to-end encrypted password manager
Password management where vault contents reach the server only as ciphertext
KeyCare Pass stores passwords, passkeys, payment cards, identities, secure notes and SSH keys in a vault that is encrypted on the user’s device before anything is synced. Organizations share credentials through collections and groups, enforce two-step login and master password rules by policy, and keep an event log of who viewed, changed or shared what. Run it on the hosted service in the European Union or on your own Docker host.
KeyCare Pass gives each person a private vault and gives organizations shared collections on top of it. The master password never leaves the device: it is stretched into a master key with PBKDF2-SHA256 or Argon2id, and that key protects a random account key which encrypts every item field, names included, with AES-256 and authenticates it with HMAC-SHA256. The service stores and synchronizes ciphertext, which is why it cannot reset a forgotten master password and why a breach of its servers would not expose vault contents.
For teams, the organization is the unit of control. Owners and admins invite members, confirm them after comparing a fingerprint phrase derived from the member’s public key, assign them to groups and collections, and revoke or remove them when they leave. Business and Enterprise plans add policies such as required two-step login, master password rules, generator rules and single-organization membership, plus account recovery for enrolled members. Admins manage access to shared items and are not given the keys to anyone’s personal vault.
KeyCare Pass is part of the GovPAM product family, and it is open source: the apps are licensed GPL-3.0 and the server AGPL-3.0, and a source archive is published for each release that runs the hosted service. A security team can check the published whitepaper against the code instead of taking the design on trust. The product was previously called KeyGuard Password, and accounts, vaults and the browser extension carried over unchanged.
Capabilities
Built in, not bolted on
Encrypted vault and autofill
One vault holds every credential type a person or team needs, encrypted field by field before it leaves the device.
Logins, passkeys, payment cards, identities, secure notes and SSH keys
Autofill from the page, the toolbar or the right-click menu, and an offer to save new and changed logins at sign-in
HTTP basic-authentication prompts filled from the vault
Encrypted file attachments on any item, up to 1 GB per person
Import from other password managers and browsers, and export at any time
Generator and vault health
Reports show where a vault is weak, and the generator replaces what they find without anyone having to invent or remember a password.
Random passwords, passphrases and usernames on demand, with generator rules set by policy
Reports for weak, reused and exposed passwords, unsecured websites and missing two-step login
Exposed-password checks by k-anonymity: only the first five characters of a SHA-1 hash leave the device
Organization reports covering the passwords held in shared collections
Passkeys and built-in authenticator
Passkeys and one-time codes live in the same encrypted vault as the logins they protect, and a passkey can also sign in to KeyCare Pass itself.
Website passkeys saved in the vault and used to sign in
Passkey sign-in to the web vault; where the browser supports the WebAuthn PRF extension, the same passkey also decrypts the vault
Six-digit TOTP codes stored next to their logins and refreshed every 30 seconds
Account safeguards
Two-step login, sign-in alerts and emergency access protect the account itself, separately from the encryption that protects its contents.
Two-step login by authenticator app, FIDO2 security key, passkey, email code or Duo
Sign-in history for the last 90 days, and an email when a sign-in comes from an unfamiliar IP address
Email confirmation of new devices for accounts without two-step login
Emergency access: a trusted contact can view or take over the vault after a waiting period, unless the owner rejects the request
Sharing, collections and Send
Shared credentials are organized by team, client or system, and each member sees only the collections they have been granted.
Collections with five permission levels, from view with passwords hidden to full manage rights
Groups that give a whole team access to its collections in one step
Send: text or a file shared by an encrypted, expiring link whose key never reaches the server, with an optional password
Admin console and policies
Owners and admins run the organization from one console with sections for collections, members, groups, reporting, billing and settings.
Invite, confirm after comparing a fingerprint phrase, revoke and remove members, with bulk confirmation
Policies for required two-step login, master password rules, generator rules and single-organization membership
Policies to remove Send, the card item type or PIN access, enforce centralized ownership and set default URI matching
Account recovery administration for enrolled members on Business and Enterprise
Custom admin roles on Enterprise that limit each administrator to the rights they need
Event logs and public API
Organization activity is recorded with a time and an IP address and can be pulled into the tools your team already monitors.
Item views and changes, collection and group changes, invitations, policy edits and sign-ins
Public API to manage members, groups, collections and policies and to read event logs
Organization vault export, and import of shared credentials into collections
MSP panel
Managed service providers run every client organization from one place, without a separate seat in each.
Every client listed with plan, seats in use, payer and status
One click into a client’s Admin Console to manage its members, collections and settings
Client organization keys shared with the MSP’s key in the browser, so the service never sees them
MSP event log of clients and staff added or removed, and of staff opening a client vault
One itemized monthly bill for the clients the MSP pays for
How it works
KeyCare Pass, step by step
01Derive keysThe master password is stretched on the device into a 256-bit master key with PBKDF2-SHA256 or Argon2id, using the email address as salt. Only a further hash is sent to sign in, and the server hashes it again before storing it.
02Encrypt on deviceA random account key encrypts every field of every item, names included, with AES-256 and a fresh IV, and authenticates it with HMAC-SHA256. Attachments get their own per-file key.
03Sync ciphertextThe server stores and synchronizes encrypted items, the wrapped account key and public keys. It never receives the master password or any key derived from it.
04Confirm membersWhen an admin confirms a new member, the organization key is encrypted to that member’s RSA-2048 public key with RSA-OAEP. Both sides can compare a fingerprint phrase first to detect key substitution.
05Share collectionsCollection permissions decide which shared items each member can see, fill and change. Members never receive another member’s account key.
06Log and reviewEvent logs, sign-in history and vault health reports show who did what, from where, and which passwords need replacing. The public API carries the logs into your own tooling.
Security architecture
How your secrets are protected
The master password never leaves the device. It is stretched into a 256-bit master key with PBKDF2-SHA256 (600,000 iterations by default, adjustable to 2,000,000) or Argon2id (six iterations, 32 MiB and parallelism of four by default, adjustable to 1,024 MiB), with the email address as salt.
A random 512-bit account key, stored on the server only in wrapped form, encrypts every item field with AES-256-CBC and a random IV, and authenticates each item with HMAC-SHA256 so tampering is caught before decryption.
Changing the master password re-wraps a single key. If the master password may have been exposed, rotating the account key re-encrypts the whole vault in one step.
Each account holds an RSA-2048 key pair. Organization keys reach members only after an admin confirms them, encrypted to the member’s public key with RSA-OAEP, and a fingerprint phrase lets both sides detect key substitution.
To sign in, the client sends a hash of the master key, which the server passes through a further 100,000 PBKDF2 iterations before storing or comparing it.
Send keys travel only in the link fragment after the # sign, so the server holds Send contents it cannot decrypt.
The service sees account metadata such as email, devices, sign-in times, IP addresses, memberships and event logs. It never sees the master password, item contents, item and folder names, attachments or Send contents.
Deployment & editions
Run it the way your organization works
Hosted service: the web vault at vault.keycarepass.com, running on servers in the European Union with a PostgreSQL database and TLS on all traffic
Self-hosted: the full server on your own Docker host with PostgreSQL 16 behind your reverse proxy, licensed by installation ID with no outbound call to the vendor or a billing service
Personal editions: Premium for one person, and Families for up to six people with a shared household collection alongside each private vault
Business editions: Teams for shared collections, event logs and the public API; Business adds policies and account recovery; Enterprise adds custom admin roles. Teams and Enterprise include a 14-day trial with no card required
Available now: the web vault in any modern browser and a browser extension for Chrome, Edge, Brave, Opera and Vivaldi. Desktop apps for Windows, macOS and Linux, mobile apps for iOS and Android, and Firefox and Safari extensions are listed as coming soon
Managed rollout: force-install the extension through the ExtensionInstallForcelist policy in Google Admin, Group Policy or an MDM, or use the signed self-hosted extension package on networks that block the Chrome Web Store
Who it is for
Teams that rely on it
IT and security teams
Administrator and service logins organized by system in collections, with permissions that let a member use a password without seeing it. A policy can require two-step login across the organization, and the event log shows who viewed or changed an item and from which IP address.
Regulated and public-sector organizations
Self-host on your own Docker host so the encrypted vault, files and logs stay on infrastructure you control, under a license that needs no outbound connection. Open source code and a published whitepaper give a security review something concrete to test.
Managed service providers
Run every client organization from one MSP panel, open a client’s Admin Console in one click, and work inside client organizations without being added to each. The MSP event log records when staff open a client vault, and paid clients roll up into one itemized monthly bill.
Individuals and families
Premium covers one person and Families covers up to six, each with a private vault and a shared household collection, plus emergency access for a trusted contact and a built-in authenticator for two-step codes.
Frameworks
Controls that support your obligations
KeyCare Pass provides controls and evidence that help organizations meet these frameworks. Certification of your environment remains with your assessor.
NIS2 Article 21(2): cryptography (h), access control (i), multi-factor authentication (j) and basic cyber hygiene (g), through on-device encryption, collection permissions, a policy requiring two-step login and vault health reports
ISO/IEC 27001:2022 Annex A: access control and identity management (5.15 to 5.18), privileged access rights (8.2), secure authentication (8.5), logging (8.15) and use of cryptography (8.24)
NIST SP 800-63B and CSF 2.0: long generated secrets, checks against compromised passwords and multi-factor authentication, mapped to the PR.AA, PR.DS and DE.CM outcomes
SOC 2: the logical access and monitoring criteria, supported by roles, collection permissions and event logs with IP addresses
POPIA Section 19: security safeguards for personal information, including encrypted storage of credentials and logged access to shared items
FAQ
KeyCare Pass questions
The service cannot reset it, because it never holds the master password or any key derived from it. In Business and Enterprise organizations, an owner or admin can set a new master password for a member enrolled in account recovery; the member must change it at next sign-in, the old password is not revealed and two-step login stays on. Personal users can name a trusted contact for emergency access instead.
No. Owners and admins manage membership, policies and the collections the organization shares, but they are not given the keys to members’ personal vaults. A member joins by receiving the organization key, encrypted to their own public key, which grants access to shared collections only.
Yes. The server runs on a Docker host with PostgreSQL 16 behind your own reverse proxy, which terminates TLS. A license issued for the installation ID lets your server create organizations, and the server never contacts the vendor or a billing service; you upload a renewed license file before the current one expires. Back up the database, the state volume holding keys and settings, and the attachments together.
Not yet. Single sign-on through OpenID Connect and SAML 2.0 is listed as coming for Enterprise, and SCIM provisioning for the business plans. Today members sign in with their master password and two-step login, which a Business or Enterprise policy can require, and the public API manages members, groups and collections from your own tooling.
KeyCare Pass documents how its controls map to NIS2, ISO/IEC 27001, NIST SP 800-63B, SOC 2 and POPIA. It does not currently hold a third-party certification of its own, so instead of asking you to rely on a badge it publishes a security whitepaper and releases the source of each version it runs, and an assessor can check the design against the code.
Get started
Take the next step
See KeyCare Pass in your environment, with a walkthrough tailored to your teams and systems.