Passkeys & 2FA
A second factor for your most sensitive folders
Passwords open your vault; passkeys and 2FA guard the folders inside it. Unlock with a biometric prompt, a hardware key or a rotating code — even someone with your password can't get in.
Passkeys
Passwordless, phishing-resistant unlock
Built on WebAuthn / FIDO2. The private key never leaves your device — we only ever store its public counterpart.
Face ID & Touch ID
Unlock with the biometrics already built into your phone or laptop.
Windows Hello
Use the platform authenticator on your Windows device to verify in a tap.
Hardware security keys
Tap a FIDO2 key over USB, NFC or the hybrid transport for phishing-resistant auth.
Cloud-backed passkeys
Multi-device passkeys sync through your platform, so a single lost device isn't a lockout.
How passkey unlock works
From registration to a single tap
- 1
Register a passkey
Confirm with a 6-digit code, then create a passkey with Face ID, Touch ID, Windows Hello or a hardware key.
- 2
Bound to your device
The private key never leaves your device or your platform's secure store — we only ever keep its public counterpart.
- 3
Unlock protected folders
When you open a folder locked behind a second factor, verify with a single biometric prompt or key tap.
- 4
Manage your keys
See every registered passkey, whether it's cloud-backed, when it was last used, and remove any you no longer trust.
Two-factor authentication
Prefer a code? TOTP has you covered
Add an authenticator-app second factor with one-time backup codes for the days you don't have a passkey to hand.
Authenticator apps
Scan a QR code with Google Authenticator, Microsoft Authenticator or Authy.
Rotating 6-digit codes
A fresh TOTP code every 30 seconds, required at login and for sensitive actions.
Backup recovery codes
One-time backup codes let you get back in if you ever lose your authenticator.
Per-folder unlock
Lock your most sensitive folders behind a second factor, not just your login.
Start protecting your credentials today
Set up your encrypted vault in minutes. Your data is encrypted on your device before it ever reaches us — that's a promise backed by math, not policy.