Encrypted on your phone before it is sent. The server holds ciphertext it has no key for — not a policy, an arrangement.
What crosses between them: bytes with no key attached.
Chapter one
iPhone, iPad and Android. Every screen below is the real app.
Opening it
The ring on each tile is that category's checkup.
Finding it
Search matches titles, usernames and addresses.
Using it
Autofill puts the password where you are standing.
Authenticator
The seconds say whether the code will still work when you have typed it.
Checkup
Reused, guessable, no second factor — with the items listed.
Generator
The bit count is worked out from the settings you chose — not length × log₂(alphabet) printed beside a switch that contradicts it.
Files
Attachments are encrypted on the device, names included — "divorce settlement.pdf" says plenty on its own.
Built, not published yet. The browser vault is the way in today.
Chapter two
Three panes instead of stacked ones. One of these is written; one is not.
A native app, not the web page in a window.
There is no Windows app today. Saying otherwise would be the first dishonest thing on this page.
One-time codes, and only those.
No Mac screenshot yet: capturing one needs permission to record the whole screen.
Chapter three
The same engine in a tab. The one client you can use today.
Signing in
Argon2id at the phone's cost. About two seconds, and it should be.
Inside
The same five destinations, with room for them.
Open
Finding something and reading it are not the same click undone.
Sharing · one
You give an address; the server hands back their public key.
Sharing · two
The server could hand over its own key instead — and every screen would look exactly like this.
Sharing · three
Sealed in your browser to that person, before it is sent.
Moving in
A CSV from Chrome, Safari, 1Password, LastPass or Bitwarden. What each column was taken to mean, and every row it could not read.
Chapter four
Everyone promises not to look. The question is whether looking is possible.
The proof
What you see, and the row the server keeps for it.
How
Argon2id, 64 MiB, three passes — on your device.
Items are sealed where they were written. Two devices editing at once merge rather than overwrite.
It stores blobs and refuses stale writes. Deliberately dumb.
Alpha Password uses OPAQUE: both sides prove the password matches without the server holding anything replayable. 1Password, Bitwarden and Proton Pass do not.
What the server sees
Zero-knowledge is a claim about content, not about traffic. A server that stores your vault learns some things, and that part is usually left out.
Compared
A table that only lists wins is an advertisement. September 2026.
| Alpha Password | 1Password | Bitwarden | Proton Pass | |
|---|---|---|---|---|
| End-to-end encrypted | Yes | Yes | Yes | Yes |
| Sign-in without a password-equivalent | Yes | No | No | No |
| Open source | Yes | No | Yes | Yes |
| Run your own server | Yes | No | Yes | No |
| Built-in authenticator | Yes | Yes | Premium | Paid |
| Apple Watch app | Yes | No | No | No |
| Passkeys | Yes | Yes | Yes | Yes |
| Cards and identities | Yes | Yes | Yes | Yes |
| Emergency access | Yes | Yes | Premium | Paid |
| Breach checking | Yes, opt-in | Yes | Yes | Yes |
| On the App Store and Google Play | Not yet | Yes | Yes | Yes |
| Share without an account | No | Yes | Yes | Yes |
| Shared vaults and family plans | No, deliberately | Yes | Yes | Yes |
| Third-party security audit | Not yet | Yes | Yes | Yes |
| Windows and Linux apps | No | Yes | Yes | Yes |
Shared vaults are the row we do not intend to win. Alpha Password shares one item with one person instead.
What it will not do
The breach check is off until you turn it on, and shows what leaves first: five characters of a hash, never the password.
Nothing carries a recipient's edit back to the owner, so offering it would be a promise the stack silently breaks.
Emergency access waits the days you chose. That is a promise the server keeps, not one the cryptography enforces.
A page is fetched fresh every visit. The installed clients run code that was checked once and pinned.
The Mac app takes a copied password back after thirty seconds. A browser cannot, and Settings says so.
Get it
The same Rust core does the cryptography on every one of them.
Autofill, passkeys, files, sharing.
System autofill and passkeys.
One-time codes, and only those.
Three panes. Clears your clipboard.
The full vault, nothing to install.
Asks for one origin — yours.
Questions
No date. They are written and they run — the screens above are the real apps — but neither store listing exists yet.
No, and none is written. It has a card on this page saying so rather than being left out.
You use the recovery key from when you made the account. If both are gone, the vault is gone — nobody here holds a copy of either.
No. All three managers in the table have been. What exists instead: a published protocol specification, open source, and parameters you can read back from the server.
Yes — a CSV from Chrome, Safari, 1Password, LastPass or Bitwarden. Export is the same file, so leaving is as easy as arriving.
Yes, and generated rather than hand-taken: the phone screens from the iOS app in a simulator, the browser ones from a script that seeds a real vault. Only the server address is substituted.
Nothing yet, and there is no paid tier to upsell you to. Running your own server will stay free.
A master password nobody can reset, and a recovery key you write down. That is the whole trade, stated before you make it.