Your secrets. Your device. No cloud required.
Features β’ Why VaultNote β’ Security Architecture β’ Architecture Guide β’ Tech Stack β’ Getting Started β’ Threat Model β’ Contributing β’ License
VaultNote is a production-quality, open-source, offline-first personal vault for mobile devices (iOS & Android). It is built for individuals who demand uncompromising privacy, zero-knowledge architecture, and total control over their credentials, notes, and cryptographic secrets.
VaultNote operates 100% offline:
- No required cloud backend
- No user accounts or remote registration
- No tracking, telemetry, or analytics services
- No network transmission of sensitive material
Most password managers today operate as cloud services. While convenient, centralized vaults present significant risks: remote data breaches, provider outages, vendor lock-in, and constant background telemetry.
VaultNote returns full sovereignty to the user:
- Local Enclave Security: Cryptographic keys are anchored directly in hardware-backed secure enclaves (iOS Keychain / Android Keystore).
- True Zero-Knowledge: Your master password is never stored anywhere, unhashed or hashed.
- Air-Gapped by Design: The app functions completely without network connectivity, preventing remote exfiltration vectors.
- Transparent & Auditable: Open-source codebase designed to be audited by security researchers.
Securely store and organize diverse sensitive assets:
- Website & App Logins: Usernames, passwords, domains, auto-fill tags, and integrated TOTP.
- RFC 6238 TOTP Authenticator: Built-in 2FA authenticator with animated countdown rings, local clock drift tolerance, and 30-second cadence.
- Encrypted Secure Notes: Markdown notes with formatting, checklists, network configuration blocks, and zero-index search policies.
- Payment Cards: Credit, debit, and virtual card numbers with encrypted CVV and PIN protection.
- API Keys & Developer Tokens: Monospace display for SSH keys, bearer tokens, and cloud secrets.
- Identity Documents: Passports, driver's licenses, and national IDs.
- Recovery Codes: Dedicated storage for one-time multi-factor recovery codes.
- Biometric Authentication: Rapid biometric unlock via Face ID, Touch ID, or Android BiometricPrompt backed by hardware security enclaves.
- Per-Item Protection: Require explicit biometric authentication before revealing or copying sensitive fields on high-risk items.
- Configurable Auto-Lock: Automatic vault locking upon app backgrounding or inactivity (Immediate, 30s, 1m, 5m).
- Clipboard Sanitizer: Decrypted secrets copied to the system clipboard automatically wipe after 30 seconds.
- Anti-Snapshot Cloak: Masks the app window in system task switchers and prevents visual screen capture leaks.
- Emergency Recovery Kit: 24-word BIP-39 mnemonic phrase generation with printable export and self-audit verification.
- Duress Vault: Optional decoy workspace configuration for coercion resistance.
- Instant full-text search across item titles, usernames, websites, and tags.
- Zero-Knowledge Ephemeral RAM Index: Searches decrypt only in volatile memoryβno unencrypted search indices or cache are ever persisted to disk.
- Real-time vault hygiene score (0β100) assessing password entropy, reuse, and 2FA coverage.
- Offline leak detection comparing credentials against local hash tables with zero network calls.
- Encrypted Export (
.vaultnote): Tamper-evident authenticated backups encrypted with AES-256-GCM and unique Argon2id key derivation parameters. - Import Support: Migration tools for importing existing vaults from 1Password, Bitwarden, and KeePass.
VaultNote implements a multi-tier cryptographic key hierarchy to ensure that ciphertext remains inaccessible without the master password or hardware-enclave biometric release.
Master Password
β
βΌ
Argon2id Key Derivation
(m=64MB, t=4, p=4, Salt)
β
βΌ
Key Encryption Key (KEK)
β
βΌ
Unwraps via AES-256-KW / GCM
β
βΌ
Vault Encryption Key (VEK)
β
βΌ
AES-256-GCM Authenticated Encryption
(Unique 96-bit Nonce per item/payload)
β
βΌ
Local Encrypted SQLite DB
- No Custom Cryptography: All cryptographic operations leverage vetted, standard implementations (Argon2id, AES-GCM, CSPRNG).
- Key Separation: The Master Password derives a Key Encryption Key (KEK). The Vault Encryption Key (VEK) is generated using a CSPRNG and encrypted with the KEK. This allows changing the master password without re-encrypting the entire vault.
- Authenticated Encryption: AES-256-GCM guarantees both confidentiality and integrity, detecting any payload tampering.
- Secure Key Storage: Keys are held in RAM only while the vault is in the
UNLOCKEDstate and are aggressively purged uponLOCKEDorBACKGROUNDtransitions.
| Layer | Technology |
|---|---|
| Framework | React Native (0.86+) & Expo (SDK 57) |
| Language | TypeScript (Strict Mode) |
| Routing | Expo Router |
| State Management | Zustand |
| Persistence | expo-sqlite |
| Secure Key Storage | expo-secure-store (Keychain / Keystore) |
| Biometrics | expo-local-authentication |
| Forms & Validation | React Hook Form & Zod |
| Testing | Jest, React Native Testing Library, Maestro |
VaultNote follows a modular, feature-oriented clean architecture:
apps/
βββ mobile/
βββ app/ # Expo Router file-based navigation
β βββ _layout.tsx # Root layout, providers & session guards
β βββ index.tsx # Entrypoint & lock redirection
β βββ (auth)/ # Authentication & onboarding routes
β β βββ setup.tsx # Master password & enclave initialization
β β βββ unlock.tsx # Biometric & password unlock screen
β β βββ recovery.tsx # BIP-39 emergency kit restoration
β βββ (vault)/ # Authenticated vault routes
β βββ _layout.tsx # Main navigation & bottom tabs
β βββ index.tsx # Vault home dashboard
β βββ search.tsx # Ephemeral search screen
β βββ favorites.tsx # Starred & pinned items hub
β βββ item/
β β βββ new.tsx # Add secret modal / selector
β β βββ [id].tsx # Detail view, mask & unmask
β βββ settings/
β βββ index.tsx # Settings overview
β βββ security.tsx # Security center & policy controls
β βββ backup.tsx # Export, import & recovery tools
βββ src/
βββ features/ # Feature modules
β βββ authentication/ # Master password, unlock & session
β βββ vault/ # Item CRUD, indexing, schemas
β βββ totp/ # RFC 6238 engine & countdown timers
β βββ password-generator/ # CSPRNG generator & entropy scoring
β βββ search/ # In-memory query evaluation
β βββ security-center/ # Hygiene scoring & breach auditing
β βββ backup/ # Encrypted serialization & export
βββ core/ # Low-level infrastructure & singletons
β βββ crypto/ # Argon2id, AES-GCM, CSPRNG primitives
β βββ database/ # SQLite connection & migrations
β βββ storage/ # Platform SecureStore bridge
β βββ biometric/ # Local authentication wrapper
β βββ clipboard/ # Auto-expiring clipboard manager
β βββ session/ # VaultSessionManager state machine
βββ components/ # Design system primitives & components
βββ theme/ # Design tokens (colors, spacing, typography)
βββ types/ # Global domain models & contracts
VaultNote is designed to feel like Apple Notes + 1Password + Linear:
- Theme: Deep obsidian palette (
#0D0E11/#121214), dark elevated surfaces (#1A1B1F), and crisp borders (#2A2B32). - Accents: Subtle lavender/purple primary (
#7B61FF), emerald security indicators (#10B981), and warning amber (#F59E0B). - Typography: Monospace accents for tokens, keys, and hashes; clean sans-serif typography with strict hierarchy.
- Micro-interactions: Smooth transitions, tactile haptic feedback, and clear visual state indicators.
- Node.js (v18 or higher recommended)
- npm or yarn
- Expo CLI
- iOS: macOS with Xcode and CocoaPods (for iOS Simulator or native build)
- Android: Android Studio & Android SDK (for Android Emulator)
-
Clone the repository:
git clone https://github.com/deadlium/vault-note.git cd vault-note -
Install dependencies:
npm install
-
Start the development server:
npm run start
-
Launch on a target platform:
- iOS Simulator: Press
iin the Expo terminal or runnpm run ios - Android Emulator: Press
ain the Expo terminal or runnpm run android - Expo Go / Physical Device: Scan the terminal QR code with the Expo Go app or a development build.
- iOS Simulator: Press
Quality and security testing are paramount for VaultNote:
# Run unit and cryptographic tests
npm test
# Run test suite with coverage report
npm test -- --coverage
# Typecheck with strict TypeScript
npm run typecheck
# Lint codebase
npm run lintE2E user flows (vault creation, biometric unlock, credential entry, TOTP verification, and emergency recovery) are automated with Maestro:
maestro test .maestro/vault-lifecycle.yamlA detailed threat model is maintained in docs/threat-model.md.
- Device Theft / Physical Database Extraction: Data at rest is encrypted with AES-256-GCM using keys never written to disk unencrypted.
- Stolen Backups: Backups are independently encrypted with unique key derivation salts.
- Clipboard Snooping: Sensitive fields copied to the clipboard are purged automatically after 30 seconds.
- Application Switcher Snooping: Anti-snapshot cloaking prevents background snapshots from capturing plaintext secrets.
- Offline Brute-Force Attacks: Argon2id parameters enforce substantial memory and computation costs per guess.
- Compromised Operating System: Jailbroken or rooted devices with kernel-level malware or active keyloggers can compromise memory safety.
- Hardware-Level Extraction: Extremely sophisticated hardware attacks bypassing the Secure Enclave are outside mobile app mitigation capabilities.
- Social Engineering: User disclosure of master passwords or recovery seeds cannot be prevented by software alone.
If you discover a security vulnerability or potential cryptographic flaw in VaultNote, please review our SECURITY.md guidelines and contact our security team directly at security@vaultnote.app (or via our encrypted PGP key) rather than opening a public issue.
We welcome contributions from privacy advocates, developers, and security auditors! Please read our CONTRIBUTING.md and CODE_OF_CONDUCT.md before submitting pull requests.
VaultNote is licensed under the MIT License. Copyright Β© 2026 VaultNote Contributors.