Zero-knowledge by design

Your credentials, encrypted before they ever leave your device.

Dyno Lockeris an end-to-end encrypted password and secrets manager for teams. We can't read your data — and that's exactly the point.

AES-256-GCMPBKDF2 · 100kSHA-256Zero-knowledgeWebAuthn / Passkey
a8F3$kL9
Zx2!qW7p
v0R#mN4t
Lp6&hJ1c

Why you can trust us

Security you don't have to take on faith

Four guarantees built into the architecture — not bolted on as policy.

End-to-end encrypted

Secrets are encrypted in your browser. We never receive your plaintext — not your passwords, not your keys.

Zero-knowledge

Our servers only ever store ciphertext, hashes and salts. Even we can't read what's inside your vault.

You hold the keys

A 12-word recovery phrase only you know derives your keys. We store a hash of it — never the phrase itself.

Full audit trail

Every create, read, copy, view and login is logged per item, so nothing happens in your vault unseen.

How information flows

The server never sees your secrets

Encryption happens in your browser. Only unreadable ciphertext is ever transmitted or stored.

Your device

Plaintext lives here only. It's encrypted in your browser with AES-256-GCM before anything is sent.

password: ••••••••

→ encrypt()

ciphertext only

DynoLocker server

blind

Stores only encrypted blobs, hashes and salts. No keys, no plaintext — nothing readable.

9f2a1c…e7b4 (AES-GCM)

iv: 3b8f…d1

How it works

The life of a single secret

From the moment you save it to the moment you read it back — encrypted the whole way.

Read the full walkthrough
  1. 1

    Set up your vault

    Generate your 12-word recovery phrase. It appears once, on a timed screen — write it down and store it offline. We keep only a hash.

  2. 2

    Add a credential

    As you save a password or secret, it's encrypted right there in your browser with AES-256-GCM and a fresh random IV.

  3. 3

    Sync securely

    Only the encrypted blob travels to our servers. The plaintext never leaves your device.

  4. 4

    Access on demand

    Data is decrypted locally, only after you unlock with your phrase and any required second factor.

  5. 5

    Share with your team

    Grant role- and permission-based access to folders and items — still end-to-end encrypted throughout.

  6. 6

    Stay accountable

    Every access is recorded in a tamper-evident audit log, so nothing happens unseen.

Encryption explained

Real cryptography, in plain language

A look at the building blocks that keep your vault sealed.

Zero-knowledge

Zero-knowledge by design

Nobody at Bizhub can read your data. A breach of our servers exposes unreadable ciphertext, not your secrets.

AES-256-GCM

Authenticated AES-256-GCM encryption

Identical passwords never look the same when stored, and corrupted or altered data simply won't decrypt.

PBKDF2 · 100k · SHA-256

Hardened key derivation

Guessing your phrase by brute force is deliberately slow and expensive, even with specialized hardware.

Features

Everything a team needs, nothing it doesn't

Encrypted folders & credentials

Organize passwords and secrets into folders, all encrypted client-side.

Encrypted file storage

Store certificates, keys and documents with the same zero-knowledge encryption.

Passkeys & 2FA

Lock sensitive folders behind WebAuthn passkeys or TOTP codes.

Change logs & versioning

Track every change to an item with full historical change logs.

Roles & granular permissions

Control exactly who can view, edit or manage each folder and item.

Active session management

See and revoke active sessions across devices at any time.

Start protecting your credentials today

Set up your encrypted vault in minutes. Your data is encrypted on your device before it ever reaches us — that's a promise backed by math, not policy.