Vault Solo
The vault on its own, if you want nothing else from the stack yet.
- Unlimited items
- Passkeys & TOTP
- Breach & reuse alerts
- All devices
Everything is encrypted before it leaves your device with a key derived from your master password. If we were breached tomorrow an attacker would walk away with noise — and your logins come bundled with the rest of the stack.
[ THE UNCOMFORTABLE PART ]
Not that they do. But architecture beats intent: if the key derivation happens anywhere but your device, or the master password ever reaches a server, then a breach, a court order or a bad hire is enough. Password managers have been breached — and when it happened, the vaults went with them.
The average person reuses one password across 14 accounts. One breach unlocks all of them.
Encrypted vault archives have been stolen wholesale, then attacked offline at leisure.
Old iteration counts turn "encrypted" into "brute-forceable on rented hardware".
Even sealed vaults often leak which sites you hold accounts on.
# row 41,208 — full record
user_id 0x7f3a…c19d
blob 9f2c44e1b70821da4a77e2c091bd
blob c0817ee930ab5f14b3e508cf27ae
kdf argon2id · m=64MiB t=3
key — not present —
sites — not present —[ ARCHITECTURE ]
This is the whole design. There is no branch where a server sees a secret, because there is no server-side key at all.
It exists in memory on your machine for a moment and is never transmitted, never logged, never recoverable by us.
A memory-hard function turns the password into a key, locally. Tuned so guessing costs real money per attempt.
Site names, usernames, notes, TOTP seeds — all of it inside one authenticated blob. Nothing is stored alongside in the clear.
Sync moves opaque blobs between your own devices. We can tell you have a vault. We cannot tell you anything about it.
[ WHAT YOU GET ]
Your vault is checked continuously against 19 billion leaked credentials — using a private set intersection, so we learn nothing about what you hold. When something appears, you get a notification with the affected site and a one-tap rotation.
shop.example appeared in a breach
Disclosed 4 hours ago · 2.1M accounts · your password was reused on two other sites.
Passkeys sync end-to-end encrypted across your devices. Two-factor codes live next to the login they belong to. Cards, addresses, recovery phrases and secure notes sit in the same sealed blob — so there is nothing left over in a notes app or a screenshot.
A password manager is not a business on its own — it is table stakes for using the internet safely. So it ships with the stack rather than beside it: no separate plan, no per-seat surprise, no feature held back for a higher tier.
[ COMPARE ]
| Feature comparison | Browser built-in | Mainstream manager | ION Vault |
|---|---|---|---|
| Key derivation | Tied to your account | On device, usually | On device, Argon2id |
| Site names encrypted | No | Often not | Yes, inside the blob |
| Breach monitoring | Basic | Paid tier | Included, private lookup |
| Passkeys | Platform-locked | Varies | Portable, E2E synced |
| TOTP built in | No | Paid tier | Included |
| Works outside its browser | No | Yes | Yes, everywhere |
| Price | Free, with a catch | $3–5 / mo | $0 — in the bundle |
[ SWITCHING ]
Encrypted export in, sealed to your key on arrival, folders and tags preserved. The old file is shredded from disk when the import completes.
[ PRICING ]
It comes with every paid plan, in full. Join the waitlist before launch and the plan itself is half price for twelve months.
The vault on its own, if you want nothing else from the stack yet.
All six products on one account — vault, VPN, mail, browser, proxies and agent access.
Six people, six private vaults, and shared collections for the things everyone needs.
30-day refund · Encrypted export on demand
[ FAQ ]
You recover with a phrase generated at setup that you store somewhere physical. If both are gone, the vault stays sealed — from you and from us equally. We would rather tell you that plainly than offer a reset that quietly proves we could have opened it all along.
Private set intersection. Your device sends a blinded fragment of each hash, gets back the matching slice of the index, and does the comparison locally. We learn neither which credentials you hold nor which ones matched — the result never leaves your machine.
Yes. There are native apps for macOS, Windows, Linux, iOS and Android, plus extensions for Chrome, Safari, Firefox and Edge. Autofill, passkeys and TOTP work the same everywhere.
An account identifier, a sealed blob, and the parameters needed to derive your key on your own device — the Argon2id settings and a salt. Not the key, not the site names, not the item count in any meaningful form. Sync is blob replication and nothing more.
Export an encrypted archive or a standard file any time and import it into another manager. There is no retention period and no export fee — your data was always yours, and it was never readable by us in the first place.
Household covers six people with private vaults plus shared collections for the Wi-Fi password and the streaming logins. Shared items are encrypted to each member's key individually, so leaving the household removes access cleanly.
Vault ships alongside ION Browser to the waitlist in join order. Founding pricing on the stack is locked for twelve months from the day you sign up.
[ 04 · VAULT ]
Founding pricing across all six products, and your pick of @ice.io addresses before they go.
One launch email, no spam