A key you hold
A random 256-bit master key protects the vault. It is wrapped by your password and by a separate vault key, and it is never sent anywhere - not to us, not to the sync server.
Xvetu Solutions
sherloc is a password and secrets manager for Windows and Android. Entries are encrypted on your device before anything leaves it; the sync server holds only ciphertext, so it cannot read what it stores.
One encrypted vault, on the devices you already own.
sherloc keeps passwords, notes, cards and other secrets in one encrypted vault. It runs on Windows and on Android, and the same vault opens on every device you connect - no account, no shared master password sent anywhere.
It is a product of Xvetu Solutions, built around a small, self-contained crypto core. Sync is optional: a vault is a file of your own, and if you turn sync on it travels as ciphertext to a server that stores it without being able to read it.
Zero-knowledge in one paragraph: the key never leaves the device.
A random 256-bit master key protects the vault. It is wrapped by your password and by a separate vault key, and it is never sent anywhere - not to us, not to the sync server.
Each entry is sealed with AES-256-GCM under its own key, derived with HKDF-SHA256 from the master key. One entry being exposed does not open the others.
If you turn on sync, the server stores ciphertext and a revision number. Even a fully compromised server returns no password and no key, because it never had them.
The building blocks are standard. Argon2id turns your password into a key, then AES-256-GCM, HKDF-SHA256 and the operating system's CSPRNG do the rest - in our own composition. We do not invent ciphers.
What the app does today.
What is actually in place, and what we do not claim.
The code has been through a security review. Every critical finding was fixed, and the remaining ones are tracked in the repository rather than forgotten.
The app sends nothing on its own - no usage statistics, no logs. Update checks, sync and error reports run only when you start them, and the log stays on your device.
There is no background network activity. The app reaches the network when you press a button, and nowhere else.
Lose both your password and your vault key and the data is gone for good. We cannot recover it, and neither can anyone else - that is the price of nobody else being able to read it.
This page holds the same rule. It sends nothing anywhere: its own rights
declare connect-src 'none', and there is no script in it.
Builds are served by this site, next to their checksums.
The version, the file names and the SHA-256 of every build are published next to the files themselves, in version.json, so you can check what you downloaded before you run it.
Windows builds are not yet code-signed. SmartScreen will warn about an unknown publisher; this is expected. Until signing is in place, the published checksums are how you verify the file.