Store data online that only you can read.

Cryple is a zero-knowledge vault for the things you cannot afford to lose: passwords, seed phrases, notes, documents and files. Everything is encrypted in your browser before it is sent, and the keys are derived from a recovery phrase only you hold.

Everything in one vault

  • Secrets
  • Notes
  • Documents
  • Drive
  • Safe sharing
  • Passwords

Why is Cryple Different?

Every vault claims zero-knowledge. Post-quantum is a line on someone's spec sheet. Cryple is all three at once, and it is the combination — not any one of them — that nobody else is shipping.

A glowing padlock over a field of digital data
Zero-Knowledge

Zero-Knowledge by Construction, Not by Policy

Every item gets its own random key, generated on your device and wrapped under a key derived from your recovery phrase. What reaches our servers is a sealed blob and the little that routing needs — its size, and when it changed. There is no master key, no recovery database, no support tool that opens your vault. Not because we promise not to look, but because there is nothing on our side to look with.

A confident woman in sunglasses on a city street

You Are Not The Product

No ads, no tracking, no cookies. Our free tier is genuinely free, and you pay when you want more room. Zero-knowledge is the architecture, not the marketing: the locks and the keys are made on your device, and we cannot see your passwords, read your notes, or open your files under any circumstances.

A man working at a standing desk by a window

Everything You Actually Need to Keep

Small secrets that unlock everything else — seed phrases, account details, credentials. Notes for the things that need explaining. Long-form documents that sync across your devices as you write. Encrypted files are next. One vault, one phrase, every kind of thing you would otherwise scatter across a notes app, a drive and a drawer.

A man at his desk reading on his phone next to an open laptop

Write on One Device, Read on Any Other

Documents sync as you type, encrypted the whole way. Your devices agree on the text without our servers ever seeing it — they store and forward sealed changes and merge nothing. Open a new browser, type your phrase, and everything is simply there.

A single key lying on a dark surface

What You Get Instead of a Reset

We considered letting trusted contacts hold pieces of your key and decided against it: any door built for you is a door that exists. So we give you the artifact instead — a printable kit at sign-up, and plain words about what you are responsible for, before you are responsible for it.

A steel backup plate for a recovery phrase on a pile of word tiles
BIP39 Authentication

Your Recovery Phrase Is the Account

Twelve or twenty-four ordinary words, generated in your browser. Every key Cryple uses is derived from them the same way on every device — no email, no password. Type the phrase into a new browser and your vault is simply there. It also means nobody can let you back in, including us: the phrase is the account, so losing it loses everything, which is why we make you verify your copy before you begin.

An eye peering through a hole in a dark wall

Paranoid Mode — a 6-Digit PIN as a Second Factor

Both modes use a 6-digit PIN to lock the app and encrypt the copy of your phrase on that device. In Standard mode it stays local — forget it and you sign back in with your phrase, losing nothing. In Paranoid mode the server checks it too, so a stolen phrase alone gets nobody in. That protection is real and so is its cost: a forgotten PIN ends a Paranoid account, and we say so on the screen where you turn it on.

A cheerful woman in sunglasses making peace signs
Post-Quantum

Already Beyond Quantum Reach

Your vault is sealed with AES-256 keyed from your phrase, and symmetric encryption is precisely what survives a quantum computer — Grover's algorithm halves the exponent and nothing more. What a quantum computer does break is public-key cryptography, and that is only needed when two people who share no secret must agree on a key. So the exchange behind private sharing combines a classical algorithm with a post-quantum one, and an attacker has to break both. It is implemented, specified, and machine-checked against fixed test vectors.

Secure Your Early Access

Join our waitlist today and secure your spot in our upcoming releases.

September 2026

Staging Release

Live now: the vault, encrypted notes and long-form documents that sync across devices, in both Standard and Paranoid mode.

Encrypted file storage — images and PDFs. The place for the documents that actually matter: contracts, medical records, passports, IDs. Sealed on your device exactly like everything else. Private sharing follows: send one item to one person, still end-to-end.

December 2026

The Drive

2027

Production Launch

No date yet. The vault opened to everyone.

Join the waitlist to be notified about the official launch. During the first month of release, premium subscriptions will have a 50% discount.

How It Works

You set it up once, in a couple of minutes, and after that it just holds things.

Illustration of generating a recovery phrase

1. Generate Your Recovery Phrase

Open Cryple and your browser generates twelve or twenty-four words, then derives your whole key tree from them locally. Nothing is sent anywhere. Write the phrase down on paper, and choose Standard or Paranoid mode.

Illustration of a secured vault

2. Fill the Vault

Store the small things that unlock everything else — seed phrases, account details, credentials. Write notes: the letters and instructions that explain them. Write long-form documents that sync across your devices. All of it encrypted here, before it leaves.

Illustration of opening the vault from any device

3. Open It Anywhere

Your phrase is the account, so a new browser needs nothing else. Type it in and your vault is there, decrypted locally. Set a 6-digit PIN on each device so coming back is six digits rather than twelve words.

Illustration of storing the recovery phrase safely

4. Put the Phrase Somewhere Real

Print the kit we give you at sign-up, or write the words on paper, and store it where you would keep a passport. This is the one part we cannot do for you, and the one part that matters most: nobody — us included — can issue you another.

Security You Can Verify

Zero-knowledge by construction, not by policy: the server never receives anything readable, because the keys are made on your device and never sent.

  • Everything is encrypted in your browser; the server receives sealed data and stores it
  • Zero-knowledge by construction — there is no key on our side to decrypt with
  • Proof of ownership by ECDSA P-256 signature over a fresh challenge, never a transmitted secret
  • Your data at rest is AES-256-GCM — symmetric, and already beyond the reach of a quantum computer
  • Hybrid PQXDH for encrypting to another account: X25519 + ML-KEM-768 combined, so a classical and a quantum attack must both succeed
  • Paranoid Mode: a real second factor, requiring your recovery phrase and your PIN together
  • Your recovery phrase, your PIN and your plaintext never leave your device, ever
  • No account recovery of any kind, by design — there is no path back in for us to be compelled to use

Technical Specifications

  • Symmetric Encryption: AES-256-GCM
  • Classic Key Exchange: X25519 (ECDH)
  • Post-Quantum KEM: ML-KEM-768 (FIPS 203) — for sharing
  • Hybrid Protocol: PQXDH (X25519 + ML-KEM-768) — for sharing
  • Key Derivation: BIP39 → SLIP-0010 P-256
  • Authentication: ECDSA P-256 Signatures
  • PIN Stretching: PBKDF2-SHA256 (600k) client-side
  • Server Hashing: Argon2id (64 MiB, t=3, p=4)