Skip to content

end-to-end encryption

Your vault. On every device.

Pairing takes one scan and no account. One device shows a code, the other scans it, and both show the same eight digits — confirm they match and the two are paired for good. Add as many devices as you need; each one pairs once and stays in step from then on.

After pairing, your devices reach each other through a relay — ours by default, or one you host yourself. It splices two connections together and nothing more: every byte is encrypted end-to-end — the relay never sees inside your vault. Pairing uses Noise NK with an 8-digit SAS the user confirms; every sync run then opens with a fresh Noise KK handshake, and no vault byte moves until both sides have authenticated.

01

Scan to pair

One device shows a code carrying a relay address and a single-use token. The other scans it, and ephemeral X25519 keys are exchanged over Noise NK.

02

Confirm the digits

Both devices show the same eight digits, derived from the handshake itself. They only pair if you confirm they match — which is what a machine in the middle cannot fake.

03

Mutual auth, every time

Noise KK handshake with long-term keys. ChaCha20-Poly1305 transport, padded frames, delta sync by last-write timestamp.

04

Add more devices

Each new device pairs once and joins the rest. Your vault converges across all of them wherever they are — no reconfiguration, and revoking one stops it receiving changes.

the architecture

How Peach is different.

Every major password manager works the same way: you create an account, they store your vault on their servers, and you retrieve it when you log in. That means the company can see your vault data, a server can be breached, and your account can be locked or deleted.

Peach doesn't work that way. Your vault lives on your device — encrypted with a key only you hold. There is no hosted vault to retrieve it from, no account to log into, and no central database that can be breached. Peach Sync moves your changes between your own devices through a relay that stores no vault or customer data; the connection stays encrypted end-to-end the whole way. If you want to move to a new device without syncing, export your vault as PeachScript or use Peach Codex to print a scannable physical backup — restore either with the backup password you set.

The backup is an encrypted snapshot of your vault — not your secrets in plain text. Without its password, it is useless data. The encryption (AES-256-GCM) and key derivation (Argon2id at 64MB) are applied before the backup is ever generated, on-device, with no network involved.

Passkeys work where you browse. Peach supports them in Firefox and Chrome so you can sign in with your device instead of another password.

No hosted vault

Bitwarden, 1Password, and Proton Pass all store your encrypted vault on their infrastructure. Peach uses a relay for sync, but it stores no vault or customer data — there is no hosted vault, no account database, and no vault service to breach.

No account required

Every major manager ties your vault to an email address and password. Peach ties your vault to your device and your passphrase. No email, no company holding a reset link. Your recovery is a 12-word phrase you control — not a link sent to an inbox.

Zero-knowledge relay

The common sync model: your vault is stored on the company's servers, and they hold the keys to the door. Peach Sync passes through a relay that stores nothing and can read nothing — the connection is encrypted end-to-end between your own devices, and you can host that relay yourself or turn sync off.

Portable without lock-in

Other managers export to proprietary formats or encrypted blobs tied to their own decode logic. PeachScript backups decode on any device running Peach. Move to a new machine, restore your vault, no vendor lock-in.

advanced security

Defenses for the cases people avoid.

Two Peach Pro features built for hard edge cases: a vault that may have been extracted, and a moment where unlocking is not optional.

Canary EntriesPro

Plant a fake credential in your vault. Peach never autofills it and never suggests it — it just watches. If that password ever appears in a data breach, it means someone extracted your vault and is testing the credentials. Peach alerts you immediately.

A fake entry gives you a signal when the worst-case story stops being theoretical.

Duress VaultPro

Set a second master password that opens a separate, convincing decoy vault. At a border crossing, under coercion, or anywhere you need it — enter the duress password and Peach opens normally, showing only what you put there. Your real vault stays encrypted and invisible.

A decoy vault gives you an answer when privacy and personal safety collide.

ready to switch?

Import from any password manager. Free forever.

Go Pro — $39 Get Peach Free →