Getting started
On Windows
- Install KAPEVault from the download section. It installs for your Windows account only, with no admin rights.
- Choose a master password: at least 12 characters, rated Strong. Three or four unrelated words work well.
- Add your first item with New item. Later, press Ctrl+Shift+Space in any app to find an item without opening the window.
The installer is not code-signed yet, so Windows may say it protected your PC. Choose More info, then Run anyway.
On Android
- Install KAPEVault on a phone with Android 11 or later.
- New to KAPEVault: create a vault with a master password. Already using it on a PC: choose Restore from backup and add the phone.
- Turn on fingerprint unlock if you like. The master password is still asked for every 14 days, so you never forget it.
Item kinds
Every item has a title, tags and notes, and can name who you keep it for (Held for). There are eight kinds:
- Login
- Username, password, website and how you sign in (password, Google, Microsoft, Apple and more). Can also hold a 2FA code, backup codes, security questions and up to 10 old passwords.
- Note
- A secure note. The text stays hidden until you show it.
- API key
- Key ID, secret, web address and an expiry date. KAPEVault flags keys that are about to expire.
- Link
- A website, a Drive link, a document or a folder. On the PC, a linked folder opens inside the vault with previews.
- Payee
- Who you send money to, their wallet or bank, number and account name. On the PC, Payee Check says whether a pasted number matches someone you saved.
- Device
- A router, CCTV box, phone or laptop and what its sticker says: model, serial, IMEI, MAC, admin login, Wi-Fi name and password, and a label photo. On Windows, Scan a label reads the sticker offline.
- Thing
- A physical thing and where it is kept: the room, the spot, and whether to grab it first in an emergency. Can carry an expiry date.
- ID
- Passport, driver's license, PhilSys, UMID and more, or a type you name. The number stays hidden like a password, the optional photo stays encrypted, and IDs never show up in autofill.
Security
Your vault is one file, encrypted on your device with a key made from your master password. There is no account and no KAPEVault server.
- The master password is never saved, not even in the vault file. Nobody can reset it, including us.
- Passwords, 2FA keys, backup codes, notes, API secrets and ID numbers stay hidden until you show or copy one.
- A copied password clears from the clipboard after 30 seconds (on a phone, up to a minute if Android pauses the app), and when the vault locks.
- The PC locks after 5 minutes idle, on sleep, when Windows locks, and 8 hours after unlock by default (Settings, General, Lock after). The phone locks when you leave the app.
- Windows Hello and fingerprint unlock are optional. The master password is still asked for every 14 days.
The full picture, including what KAPEVault cannot do, is on the Trust page.
Backup and sync
KAPEVault works fully offline. Backups are optional, and they are always the encrypted file, never your data in the clear.
Cloudflare R2
- In your own Cloudflare account, create an R2 bucket and an API token with Object Read & Write on that bucket only.
- On the PC: Settings, Backup, Cloud backup. Paste the bucket's S3 API URL, the key ID and the secret, then Connect.
- From then on, each change is backed up about 10 seconds later.
The bucket keeps your newest 20 backups, plus the newest of each day for 60 days.
Add a phone
- On the PC: Settings, Backup, Add a phone. A code shows for one minute.
- On the phone: Restore from backup, then scan the code.
- Type your master password. The PC and phone now sync through your bucket.
Changes merge item by item, and old passwords stay in history on both.
Keep a copy in a folder
On the PC: Settings, Backup, Keep a copy in a folder. After every change, KAPEVault writes the same encrypted file, and the Forever Opener, into a folder you pick. Pick a OneDrive, Google Drive or Dropbox folder and that app uploads it for you. Save encrypted copy, on the same screen, makes a one-off copy anywhere.
Recovery
Lost or wiped both devices? You need a backup (your bucket, your copy folder or a saved copy) and your master password.
- Install KAPEVault.
- On a PC, choose Restore from backup on the lock screen, then Cloud (your R2 URL and keys) or File. On a phone, choose Restore from backup, then scan your Emergency Kit, type the keys, or pick Use a file instead (Google Drive, Files or a USB drive).
- Type the master password the backup was made with.
Any backup in the list can be restored, older ones included. On a PC, a restore keeps the vault it replaces first, so picking the wrong backup can be undone.
Every way back in, from a second synced device to what uninstalling keeps, is on the Trust page.
The Emergency Kit
A one-page printout from Settings, Backup: a box to write your master password by hand, where your vault lives, your R2 details and the recovery steps. Tick Include the R2 keys and it also prints a code a phone can scan to restore. Once filled in, treat it like cash.
The Forever Opener
KAPEVault Opener.html opens a vault file in any browser, offline and read only, even with KAPEVault gone. It is saved beside every encrypted copy, in your copy folder and in your bucket. Its SHA-256 is shown in Settings and on the Emergency Kit, so you can check it is the real page.
Only a forgotten master password cannot be recovered. Nobody can open a backup without it.
Air Wall
Windows only. Settings, Security, Keep KAPEVault offline adds a Windows Firewall rule that blocks KAPEVault from the internet. Windows enforces it, not the app.
- Switching it on or off asks once for admin rights.
- Test tries one connection and tells you whether Windows blocked it.
- Cloud backup and sync still work: Windows' own curl carries the encrypted files, never your R2 secret key.
- It needs Windows Firewall on. If another firewall has turned it off, KAPEVault says the rule is not enforced.
More questions
Short answers are in the FAQ. How KAPEVault handles your data is on the Trust and Privacy pages.