Security
How KeyCare Pass protects your data
Your vault is encrypted on your device before anything reaches our servers. Here is how that works, what we can and cannot see, and how to report a problem.
- AES-256 encryption
- PBKDF2-SHA256 or Argon2id
- Zero knowledge
- Open source
- Hosted in the EU
Zero knowledge, in four steps
GovPAM runs the service, but only you hold the key to your vault.
Your master password stays with you
Your device turns it into a master key with PBKDF2-SHA256 (600,000 iterations by default) or Argon2id. The master password itself is never sent.
Your account key encrypts everything
A random account encryption key, protected by your master key, encrypts every item with AES-256 and authenticates it with HMAC-SHA256.
Our servers store ciphertext
What reaches the server is already encrypted. Without your master password, it cannot be read, by us or anyone who breaks in.
Sharing uses public keys
Organizations share a key with each member by encrypting it with that member's RSA-2048 public key, after an admin confirms them.
What GovPAM can see
To run your account we hold some data unencrypted.
- Your email address, name and account settings
- The devices you sign in from, sign-in times and the IP addresses of requests
- For organizations: memberships, groups, policies and, when on, event logs
- How much encrypted data and how many files you store
What GovPAM cannot see
Everything that matters stays encrypted with keys only you hold.
- Your master password: we never receive it
- Your passwords, passkeys, notes, cards, identities and SSH keys
- The names of your items and folders, and their attachments
- The contents of a Send: the key travels only in the link
Protecting your account
Two-step login
Authenticator apps, FIDO2 security keys and passkeys, codes by email, or Duo. Keep your recovery code somewhere safe.
Sign-in activity and alerts
See every sign-in from the last 90 days with its device and IP address; we email you when your account signs in from an address it has not used lately.
Log in with a passkey
Sign in to the web vault with a passkey instead of your email and master password.
Rotate your encryption key
If you think your master password was exposed, change it and rotate your account encryption key in one step.
Choose your key derivation
Raise PBKDF2 iterations, or switch to Argon2id, under Settings > Security > Keys.
Fingerprint phrase
Compare a phrase derived from your public key before an admin confirms you or you confirm an emergency contact.
Open source
Read the code that protects you
The KeyCare Pass apps are licensed under GPL-3.0 and the server under AGPL-3.0. We publish a source archive of every release that runs our service.
Infrastructure
Where it runs
Our cloud service runs on servers GovPAM operates in the European Union, behind TLS. Account emails are sent through Cloudflare Email Service and payments are handled by PayFast, which keeps card details on its side.
Responsible disclosure
Found a vulnerability? Tell us.
Email security@keycarepass.com. We read every report and will work with you to fix the problem.
Please include
- What you found and where: the app, version or address
- Steps to reproduce it, and what an attacker could do
- How to reach you, and whether you would like to be credited
Please do not
- Access or change data in accounts that are not yours
- Run denial-of-service tests, spam or social engineering
- Share details publicly before we have had a reasonable time to fix it
Questions about the security of your own account go to support@keycarepass.com. We never ask for your master password.
Frequently asked questions
If GovPAM is hacked, are my passwords exposed?
An attacker who copied our database would get encrypted vaults. Each one is protected by its owner's master password, which we never have, so a strong, unique master password is what keeps your vault safe.
Can GovPAM recover my vault if I forget my master password?
No. Nobody else has your master password or the key it protects. Organizations on Enterprise can enrol members in account recovery; otherwise, use your hint or emergency access.
Has KeyCare Pass been audited?
KeyCare Pass does not hold a certification or publish third-party audit reports. Its source code is open, and our whitepaper documents its design.