Zero-knowledge architecture
In KeyZula, encryption happens on your device, not on the server. Your master password is turned into a key on your device with Argon2id; the master password itself is never sent to the server. Every item in your vault has its own random key, and the item's name, username, website address and type are part of the encrypted data too.
The server syncs the encrypted data between your devices but can't read it. The full list of what the server can and can't see is on the How it works page.
Cryptography
For sharing, every user has an X25519 key pair, and a collection key is sealed to the recipient's public key. When a new member is added, the admin compares the member's key fingerprint with them over a separate channel; this stops the server from slipping in a fake key. Service account tokens use the same mechanism.
If our servers are breached
An attacker only gets encrypted vault data; the contents, including item names and website addresses, can't be read. Your master password isn't on the server; the server only stores a separate verifier derived from it, hashed again with Argon2id.
The following information the service needs to work is not encrypted: your email address and name, item count and update times, organization name, members and permissions, the device and IP address you signed in from, and access logs (the item's ID, never its name or contents).
That's why a long, unique master password is your most important protection: someone who steals the encrypted data can only open the vault by guessing your master password, and Argon2id makes every guess deliberately expensive.
Account protection
- Two-step sign-in with an authenticator app, plus a recovery code
- Passkey sign-in; no master password on trusted devices
- Email alerts for sign-ins from unrecognized devices; sign out sessions remotely
- Auto-lock when idle, and the clipboard clears itself
- Admin-approved devices in organizations that use SSO; an admin recovery is clearly disclosed to the member
- Access logs of personal vault items are visible only to the vault's owner
Infrastructure and connections
Our servers are in Türkiye. All connections use HTTPS only (HSTS). The web vault is served with a strict Content Security Policy and contains no analytics or advertising scripts.
When you delete your account, your data is deleted and removed from backups within 14 days. Details are in the Privacy Policy.
What we haven't done yet
- Our source code is not open.
- We're working on self-hosting; it's coming soon.
- We show our strengths and gaps against competitors openly on the Compare page.
Reporting a vulnerability
If you've found a security vulnerability, please tell us before sharing it publicly: email info@keyzula.com with "Security" in the subject line, and describe the issue, how to reproduce it and its possible impact. You can write in English, Turkish or German.
- We review every report. Please keep the details confidential until a fix is released.
- Limit your testing to your own account; don't access other users' data, disrupt the service or use social engineering.
- Our contact details are also published in machine-readable form: /.well-known/security.txt