MystSafe overview

No cloud database

Your vault stays on your devices. Not in ours.

MystSafe apps keep your encrypted vault on trusted devices. Your selected Google Drive or GitHub account carries signed, encrypted updates between them; MystSafe does not host the vault database or run the synchronization service.

Two different models

A permanent provider vault is conventional. MystSafe is different.

Conventional password manager

  • Create a provider account
  • Create and remember a master password
  • A permanent encrypted vault is maintained by the provider
  • Devices synchronize through the vendor’s vault service

MystSafe

  • Create the vault on your device
  • Unlock through local device authentication
  • Pair another device with a short-lived QR code
  • Move signed, encrypted updates through storage you choose
  • Trusted devices verify and accept updates

This comparison describes the conventional centralized-vault model. Individual products may use different implementation details.

Device-controlled sync

Encrypted updates move through your provider. Your devices decide what to trust.

Google Drive or GitHub carries signed and encrypted update blocks between your trusted devices. It does not receive the keys needed to decrypt your vault payloads.

Mac local vault
Keys stay on device
Google Drive / GitHub
sync provider
Cannot decrypt vault payloads
iPhone local vault
Keys stay on device
Signed and encrypted update blocks move through the selected Google Drive or GitHub account. Trusted devices verify signatures, membership, integrity, and replay state before accepting them.

Keep your vault under device control

Use your chosen provider to synchronize encrypted updates without a MystSafe-hosted vault database.