Vaulted

Trust center

Same vault. Same encryption. More you can do with it.

Vaulted doesn't store, host or see your vault. It signs in to the Bitwarden or Vaultwarden account you already use, decrypts on your device, and adds features on top. This page shows exactly how, what the app connects to, and what isn't finished yet.

Checked against the apps' code on September 29, 2026

The short version

  • No Vaulted server holds your vault

    Your encrypted vault stays with Bitwarden or on your own server, exactly where it is today. There's no Vaulted copy to leak.

  • Your encryption doesn't change

    Vaulted uses Bitwarden's documented end-to-end encryption. Your vault is decrypted only on your device, and your master password is never stored.

  • No third-party services

    No analytics, trackers, advertising or third-party SDKs. The app talks to your vault server; website icons come straight from each site, and you can switch them off. Crash reports go only if you choose, after you've read them.

  • Guarded on your device

    Vaulted locks after 15 minutes idle and whenever Windows locks or sleeps. Copied passwords clear after 20 seconds, and your vault's keys stay encrypted in memory between uses.

Where the risk is, and where it isn't

The data breaches that make headlines usually happen on servers, where many people's vaults sit together. Bitwarden is built so its servers only ever hold vaults they can't read, and using Vaulted leaves that protection exactly as it is.

Vaulted adds no server, database or service that stores your vault, so it creates no new copy of your data to steal. Your account, your plan and your provider's own security program stay the same.

The app is a different matter. Your vault is decrypted on your device, so the app is what you're trusting us with. The rest of this page is about the app.

How your vault moves when you use Vaulted

Your device

Vaulted

Decrypts, shows and locks your vault. Keeps an encrypted copy.

HTTPS · encrypted vault only

Your vault server

Encrypted vault

Bitwarden's US or EU cloud, or your own server. Stores your vault, encrypted, as it does today.

Vaulted's serversNot in the path. They handle licenses and updates, and never receive your vault, your master password or your vault account.

What the Vaulted apps connect to

The complete list, checked against the apps' code.

  • Your vault server

    Bitwarden's US cloud (vault.bitwarden.com, api.bitwarden.com, identity.bitwarden.com), its EU cloud (vault.bitwarden.eu, api.bitwarden.eu, identity.bitwarden.eu) or your own server over HTTPS

    WhenSigning in, syncing and saving changes
    What's sentYour email, a hash derived from your master password (never the password itself), a random ID created for this installation, two-step codes or security-key signatures, and your encrypted vault.
  • Websites saved in your vault

    Each site's own address, over HTTPS

    WhenWhile website icons are on. They're on by default; turn them off in Settings.
    What's sentA request for the site's icon, and for its main domain's icon if that fails. No cookies are sent. Like any visit, the site sees your IP address.
  • Cloudflare public DNS

    cloudflare-dns.com

    WhenOnly if you turn on the reachability check for a self-hosted server. Off by default.
    What's sentYour server's name, to check whether people outside your network could open items you share.
  • Vaulted's update feed

    vaulted.click

    WhenOnly for copies installed from this site, when your system checks for updates. Copies from an app store update through the store.
    What's sentA standard request for the feed. No vault data. The apps never check for or download updates themselves.
  • Vaulted's website

    vaulted.click

    WhenOnly when you choose to send a crash report. Vaulted asks each time, unless you choose otherwise in Settings.
    What's sentThe report you can read first: error types, error codes, where in Vaulted's code they happened, and version numbers for Vaulted and the system it runs on. No vault data, account, device ID or server address.

Nothing else. No analytics, telemetry, advertising or third-party SDKs. You can confirm this with a network monitor.

Where your data lives

  • Unchanged

    Your vault server

    Your vault, encrypted end to end, exactly as today. Vaulted's extras (tags, links, importance, expiry dates and review decisions) are saved inside your vault in one encrypted field per item, with folder and tag order in two archived items. They're encrypted, synced and backed up like everything else.

  • Encrypted

    Your device

    A copy of what your server sent, still encrypted, and sealed again by Windows for your user account (DPAPI). Settings and timed pins stay on the device. Signing out deletes the copy and its key.

  • Nothing from your vault

    Vaulted's servers

    They sell licenses, deliver updates and receive the crash reports you choose to send. They never receive your vault, your master password or your vault account.

    Licenses
    One purchase can cover more than one platform. Stripe takes the payment, so card details never reach us. We keep the license, the platforms it covers and, for each device you activate, its platform, app version and a random ID. We email your key to the address you paid with, then keep only a one-way fingerprint of that address, so the key can be sent again to it and no other. No name.
    Updates
    Copies installed from this site update from here, through Windows App Installer. Copies from an app store update through that store.
    Launch list
    Sales haven't opened yet. Until they do, the only personal data we hold is the email addresses people leave to hear about launches.
    Crash reports
    Only the reports you choose to send, after reading them: error types, error codes and where in Vaulted's code they happened. Nothing that identifies you. They're deleted after 90 days.

Protection on your device

How the Windows app treats your vault while it's open.

  • Master passwordRead from a protected input, used in memory to derive your keys, then wiped. Never written to disk.
  • EncryptionBitwarden's documented protocol: PBKDF2-SHA256 or Argon2id, whichever your account uses; AES-256 with an HMAC-SHA256 check, verified in constant time before anything is decrypted; RSA-OAEP for shared organization keys. Built on .NET's standard cryptography, plus the Konscious library for Argon2id. No homemade algorithms.
  • Keys in memoryYour vault's keys stay encrypted in memory except while they're in use. Other programs running under your account can't read Vaulted's memory unless they run as administrator.
  • Auto-lockLocks after 15 minutes without activity by default, and straight away when Windows locks, sleeps, signs out or shuts down. Locking discards decrypted items, notes and one-time-code secrets and clears them from the screen.
  • ClipboardCopied passwords and codes are cleared after 20 seconds, or as soon as you lock.
  • Windows HelloOptional. Your vault key is wrapped by a Windows Hello key that can't be exported, so your master password is never saved.
  • HTTPS onlySelf-hosted servers must use HTTPS, and certificate checks are never switched off.
  • No logs of your dataUnexpected errors are kept as a type, a code and where in Vaulted's code they happened. Error messages, which can contain usernames, server addresses or item names, are never saved or sent. Crash reports stay on your device, protected by Windows, until you send or delete them.
  • One copy runningOpening Vaulted a second time hands over to the window that's already open, so only one process holds your encrypted cache.

Releases and updates

  • Each Windows release is signed with SHA-256 Authenticode and an RFC 3161 timestamp. The release script verifies every signature and refuses to sign when a release check fails.
  • Updates come through Windows App Installer from an HTTPS feed. Windows installs only newer versions from the same signed publisher, so an older build can't be pushed to you.
  • The app never downloads or installs code by itself.

How we check our work

Every Vaulted app has unit tests, and we run an automated security suite on our changes. The suite reads each app's code for specific protections: nothing decrypted written to disk, no secrets in logs, no disabled certificate checks, no telemetry, and complete locking and clipboard clearing.

Each of those checks is tested too, against deliberately broken copies of the code, so a check that stops working gets noticed.

This website and your data

  • No cookies, analytics or tracking. Fonts and images are served from this site, and its security policy stops your browser from contacting anyone else.
  • If you register interest, we keep your email address, the platforms you chose, your language, the date and when you confirmed it. The list doesn't record your IP address, your browser or where you came from, and an address is deleted once we've emailed it about every platform it chose.
  • We email you once to confirm your address, then only to tell you when Vaulted is ready for the platforms you chose. Every email has a link to leave the list, and we never share or sell your address.
  • Our emails go through Resend, an email delivery service, which receives each address and message only to deliver them. We don't track opens or clicks.
  • Like most sites, our web server keeps access logs, which include IP addresses, to protect against abuse.
  • Questions about your data? Email [email protected].

Remove your email

Enter the address you registered. It's deleted straight away; there's nothing to confirm.

Report a security issue

Found a vulnerability? Email [email protected]. Please leave out real vault data, and give us a fair chance to fix the problem before sharing details publicly. Other bugs go to [email protected].

Vaulted is an independent client. It is not affiliated with or endorsed by Bitwarden, Inc. Bitwarden is a trademark of Bitwarden, Inc.