Security

How it’s built, plainly.

Brassword hasn’t been independently reviewed yet, so we won’t borrow words like “proven”. Here is the design, what it protects against, and what we’re still working on.

The design

No account

There’s nothing to sign up for and no server holding your vault. You can’t be locked out by an account problem, and there’s no account database to leak.

Encrypted on your Mac

Your vault is encrypted on the device with keys derived from your passphrase and a device Account Secret. Nothing decrypted is written to disk, and vault files are readable only by your user account.

Touch ID

Day-to-day unlock uses Touch ID, through a key held by the Secure Enclave, with no passcode fallback in its place.

Sync sees ciphertext

Mac and iPhone pair by QR code. The relay between them stores and forwards encrypted, signed updates. It never has your passphrase or keys.

Recovery you hold

A Recovery Key and portable encrypted backups. Restores refuse to roll back to an older copy without telling you.

A small app surface

The interface runs with no network access of its own, and the app’s Swift core does the encrypting, storing and copying.

Updated 3 October 2026

What we’re still hardening

An internal review in September 2026 gave us a list. We’re working through it before launch. Areas in progress:

  • ⌘V form filling, which is why it’s marked early and kept off the home page.
  • What happens when you remove a device from sync.
  • Locking the vault automatically with your Mac’s screen lock.
  • How copied passwords are marked for the clipboard.
  • Limits and quotas on the sync relay.
  • Release build checks.

We’ll publish details once each item is fixed, not before.

Report a vulnerability

Found something? Please tell us privately first, at security@brassword.app.