Skip to content

How KAPEVault protects you

There is no KAPEVault account and no KAPEVault server, so nobody at BrewedOps can see, reset or recover what you keep. Here is how that works, and where it stops.

Encryption

Your master password is turned into a key with scrypt (N = 2¹⁷, r = 8, p = 1) and a random 16-byte salt. scrypt is slow on purpose, so guessing passwords against a stolen copy takes a very long time.

The whole vault is sealed as one piece with AES-256-GCM, with a fresh 12-byte nonce on every save. A wrong password and a changed file both fail the same integrity check, and nothing opens.

Before any key is made, the file's settings are checked, so a planted file cannot make unlocking hang.

A new master password must be at least 12 characters and rated Strong. After 5 wrong tries in a row, each try waits longer, up to 30 seconds, even across a restart.

No account, no server

There is nothing to sign up for. KAPEVault has no analytics, no tracking, no ads and no crash reports, and BrewedOps runs no server your vault could reach.

Your master password is never saved, not even in the vault file.

What stays on your device

  • The master password and the key made from it. On the PC, locking wipes the key from memory.
  • On the PC, the unlocked vault lives only in the app's main process. The window gets a password only when you show, copy or edit it.
  • Password health (weak, reused, old) is checked on the device, and reuse is compared by hash, never in plain text.
  • Scan a label reads the photo on your PC, offline, and Read aloud uses a voice on your PC.
  • On Android, the vault sits in the app's private folder and is left out of Android backups and phone-to-phone transfers.

Your bucket, not ours

Cloud backup and sync stay off until you connect a Cloudflare R2 bucket in your own account. Only the encrypted vault file goes up, byte for byte as it sits on your device, plus the Forever Opener page, which holds none of your data.

Your R2 keys are stored inside the encrypted vault. Add a phone shows them as a code only when you ask, for one minute, and the Emergency Kit prints them only if you tick Include the R2 keys.

Give the R2 token Object Read & Write on that one bucket only, so a leaked key reaches nothing else.

Restoring asks for the master password the backup was made with, and keeps your current vault first, or asks before replacing it without a copy.

Clipboard and locking

  • A copied password clears after 30 seconds (on a phone, up to a minute if Android pauses the app), when the vault locks, and on the PC when you quit.
  • On Windows, copies are kept out of clipboard history (Win+V) and the cloud clipboard. On Android, they are marked sensitive.
  • The PC locks after 5 minutes idle, on sleep, when Windows locks, and after a set time from unlock (8 hours by default).
  • The phone locks when you leave the app: at once, after 30 seconds or after 1 minute.
  • Windows Hello and fingerprint unlock are optional, ask for the master password every 14 days, and turn off by themselves when it changes.
  • Android blocks screenshots, screen recording and the recent-apps preview of the vault.

What the app refuses to do

  • The PC window cannot reach the internet. Cloud requests are signed inside the app and carried by Windows' own curl.
  • Programs, and office files that can hold macros, are never opened from KAPEVault, only shown in Explorer.
  • Web pages in previews run with scripts off until you choose, and cannot reach the internet.
  • Air Wall, if you switch it on, has Windows Firewall block the KAPEVault app itself. Encrypted backups to your own bucket still go out through Windows' own curl. See Air Wall.
  • On Android, the camera is asked for only when you scan a code, and the code is read on the phone.

Never locked out by the app

The Forever Opener is a single web page that opens your vault file in any browser, offline, with your master password. Its security policy blocks every network request, and its SHA-256 is printed on your Emergency Kit so you can check it. If KAPEVault ever disappears, your vault still opens.

Every way back in

Most of these need a backup set up ahead of time, and all of them need your master password (for a backup, the one it was made with). Step by step: Recovery in the Docs.

Your PC died or was replaced
Install KAPEVault. On the lock screen, choose Restore from backup, then Cloud, and type your R2 address and keys. Any backup in the list works, older ones included.
Your phone was lost or reset
Install KAPEVault and choose Restore from backup. Scan the code from your PC's Add a phone or your Emergency Kit, or type the keys. The newest backup is picked; you can choose an older one.
You kept a copy in a folder
The PC writes the encrypted vault into your OneDrive, Google Drive or Dropbox folder after every change. On a PC, restore it with Restore from backup, then File. On a phone, Restore from backup, then Use a file instead.
You saved an encrypted copy
A file made with Save encrypted copy restores the same way, on a PC or a phone.
You still have one synced device
A PC and phone that sync each hold the whole vault, so the one you still have opens everything. Its backups in your bucket set up the new one.
Both devices are gone
Your Emergency Kit holds your handwritten master password and where the vault lived. With Include the R2 keys ticked, it prints the keys and a code the phone scans to restore.
KAPEVault is gone or will not run
The Forever Opener opens a vault file in any browser, offline and read only. It sits beside every saved copy, in your copy folder and in your bucket.
You restored the wrong backup
A PC restore keeps the vault it replaced first: in your bucket, marked Before a restore, or on the PC, where Settings, Backup can put it back.
You uninstall the app
On Windows, the vault stays and a reinstall finds it. On Android, uninstalling deletes the phone's vault, so set up a backup first.

None of these bring back a forgotten master password, and nobody can reset it, including BrewedOps. Fingerprint and Windows Hello do not replace it: the master password is still asked for every 14 days.

What KAPEVault cannot do

KAPEVault cannot recover a forgotten master password. Nobody can, including BrewedOps. Print the Emergency Kit and keep it somewhere safe.

  • It cannot protect you from malware on your device. A keylogger can watch you type.
  • It cannot stop someone who knows your master password, or guesses an easy one. Use a long one you use nowhere else.
  • Backups made before a master password change still open with the old password, until you choose Delete older backups (Settings, Backup).
  • OneDrive, Google Drive and Dropbox keep old versions of your folder copy, and those still open with the master password they were saved under, so after changing it, delete the old versions there too.
  • With Windows Hello on, anyone who can sign in to your Windows account (password or PIN) can open the vault with Hello, until the master password is due again after 14 days.
  • The Forever Opener is a web page, so it cannot keep a copied secret out of Windows clipboard history.
  • Anyone holding a filled-in Emergency Kit can open your vault.