Zero-knowledge · Rust-engineered · Open-source crypto

The password manager that can't betray you.

OneLocked encrypts everything on your device before it ever syncs. We never receive your master password or your decrypted data — so your protection is structural, not a promise.

Free forever for personal use
No ads, no tracking
Open-source encryption
app.onelocked.com/vault
Search your vault…
GH
Strong
AW
Strong
GW
Google Workspace
Weak
NF
Strong
SL
Strong
Vault synced · 47 items
End-to-end encrypted
AES-256-GCM encryption
Zero-knowledge architecture
Rust-engineered platform
Open-source crypto path
No plaintext vault storage
How it works

Three steps to total security.

No theatrics — just a clear path from local key derivation to encrypted sync across every device.

01

Create your vault

Set a strong master password. Your encryption keys are derived locally with PBKDF2 at 600,000 iterations — they never touch our servers.

02

Everything encrypts before sync

Passwords, cards, notes, and identities are sealed on your device. Only ciphertext ever moves across the network.

03

Access it anywhere

Your encrypted vault stays in sync across every device, while decryption stays tied to the one secret only you hold.

Features

Security that never compromises the experience.

Every workflow is built to feel polished and composed — while staying anchored in stronger technical defaults.

Zero-knowledge encryption

Data is sealed with AES-256-GCM before it leaves your device. We mathematically cannot see your passwords.

Engineered in Rust

A memory-safe backend makes reliability and performance part of the foundation — not an afterthought.

Password generator

Create uncrackable passwords and passphrases with cryptographically secure randomness, so reuse stops being the default.

Per-item vault keys

Every item gets its own key, wrapped by your master key — stronger compartmentalization for every secret you store.

Cross-platform sync

The same encrypted vault, everywhere — web and mobile — without switching products or weakening the model.

Secure team sharing

Share credentials through encrypted flows with clear permission boundaries instead of plaintext workarounds.

Cards & identities

Keep payment cards, identities, and sensitive records in the same organized workspace as your logins.

Biometric unlock

Reopen your vault with biometrics on supported devices while key material stays in the secure storage path.

Breach monitoring

Spot compromised credentials early and act before reuse or stale secrets turn into a wider incident.

Security architecture

Encryption by the numbers, not by marketing.

A security story is easiest to trust when the product shows its work. Here are the signals that matter.

AES-256
Encryption standard

Authenticated encryption with GCM keeps confidentiality and tamper detection in the same layer.

600k
PBKDF2 iterations

Heavy client-side derivation makes brute-force guessing expensive instead of cheap for attackers.

0
Plaintext stored

We never receive your master password or keep decrypted vault contents on the server.

Rust
Backend language

A memory-safe foundation removes an entire class of vulnerabilities at the source.

Read next

Security foundations

The full security model behind key derivation, encrypted storage, and admin-aware operations.

Master password stays on your device
Per-item keys enable real compartmentalization
Audit logging keeps sensitive operations reviewable
Explore security foundations
Why OneLocked

Most password managers couldread your data. We can't.

Zero-knowledge only matters when it changes the system boundary. The server should never need your secrets for the product to work.

CapabilityOthersOneLocked
Server can read your master password
Server can decrypt your vault
Open-source encryption library
Per-item unique encryption keys
PBKDF2 with 600k iterations
Memory-safe Rust backend
Pricing

Start free. Scale when your workflow does.

Begin with a free tier, move into richer personal or collaborative workflows when you need them, and talk to us when rollout complexity matters.

Free

Free

A clean starting point for personal protection and everyday vault use.

  • Core vault experience
  • Password generator
  • Premium UI foundation
Start free

Personal

Recommended
Paid

More room for sharing, files, and stronger day-to-day workflows.

  • Authenticator support
  • Secure sharing
  • Encrypted file support
Choose Personal

Enterprise

Custom

A tailored rollout path with onboarding and direct commercial support.

  • Tailored rollout
  • Procurement support
  • Direct coordination
Contact sales
FAQ

Questions, answered.

The details that matter most to security-minded people, kept straightforward.

Your data is encrypted with keys derived from your master password on your own device. We never receive your master password or your decrypted vault, so even we cannot read what you store. The server only ever holds ciphertext.

Because decryption keys never leave your device, we cannot reset your master password or recover your vault for you — that is the trade-off that makes the model genuinely zero-knowledge. We strongly recommend setting up recovery options when you create your account.

Yes. OneLocked has a free tier so you can get familiar with the product before deciding whether you need a paid plan. It is free forever for personal use.

Yes. The platform is designed to grow with you — move from solo use to shared or admin-heavy setups whenever your workflow calls for it.

Data is sealed with AES-256-GCM authenticated encryption. Keys are derived with PBKDF2 at 600,000 iterations, every item is wrapped with its own key, and the backend is engineered in memory-safe Rust.

Reach out to [email protected]. We can help with rollout planning, procurement conversations, and a tailored path into the product.

Ready to lock down your digital life?

Start free, keep your vault calm and organized, and step into richer sharing or admin workflows whenever your security needs grow.

SOC 2-aligned practices
Free personal plan, always
Zero-knowledge by default