Keyfold
Zero-knowledge, self-hosted in Zimbabwe

Your secrets, sealed on your terms.

Keyfold encrypts every password, card, and key on your device before it ever leaves. Two secrets guard your vault, so a full breach of our server leaks nothing but ciphertext, and your data never leaves Zimbabwe.

Two secrets, one vault
master password+KF-••••••-••••••-•••••
client-side encryption
XChaCha20-Poly1305
Scroll
  • Two-secret unlock
  • The server never sees plaintext
  • Self-host it yourself
  • Hosted in Zimbabwe
How zero-knowledge works

Two secrets go in. Nothing readable comes out.

Your master password is never transmitted. It is combined on your device with a 34-character Secret Key that only your enrolled devices and your Emergency Kit ever hold. Together they derive the key that unlocks your vault, and that key is never sent to us.

A weak master password alone is not enough to open your vault, and stealing our entire database is not enough either. That is the point.

On your deviceencrypted here

Master password

Chosen by you. Never sent.

Secret Key

34 chars, generated on-device.

Argon2id + HKDF

Account Unlock Key

Decrypts your vault. Lives only in memory, only on your devices.

On the servercannot read it

9f3a·c1e8·77b2·40dd·a5f0·e21c·8b94·66ae·d10f·3c72·bb18·04e9

We store your encrypted blobs and a hash of your auth key, and nothing else. A full breach of our machine leaks only this.

Everything in one vault

One vault for every kind of secret.

Logins are only the start. Keyfold stores cards, identities, API keys, SSH keys, and more from template-driven item types, each with custom fields and sections so anything you import round-trips cleanly.

Logins
Credit cards
Identities
API credentials
SSH keys
Secure notes
Bank accounts
Crypto wallets
Passports
National IDs
Servers
Software licenses
Available now

Autofill that just works

The browser extension suggests the right login for the page you are on, fills it, and offers to save new ones as you sign up.

Available now

Built-in one-time codes

Store your TOTP seeds alongside the login and fill the 6-digit code without a second app. The countdown ring is right there.

In build

Watchtower security checks

Reused, weak, and breached passwords flagged with a security score, all computed on your device. Breach checks use k-anonymity, so only a short hash prefix ever leaves.

Works where you work

One vault, wherever you are.

Each device keeps an offline encrypted cache, so a server outage never locks you out of your own passwords.

Available now

Web vault

The full vault in your browser at app.keyfold.co.zw. Everything is decrypted in the page; no secret ever touches a server, because there is no server to touch.

app.keyfold.co.zw

Available now

Browser extension

Chrome and Edge. Autofill, save-on-signup, a password generator, and search across your vaults from the popup.

Chrome · Edge

Available now

Desktop app

A ~10 MB native app with OS keychain access and global shortcuts. macOS is shipping; Windows and Linux come from the same codebase.

macOS now · Windows & Linux planned

In build

Mobile app

Android app available now with biometric unlock; install the APK from the download section. iOS is next.

iOS · Android

Keyfold on your desktop and phone

The native app, right where you work.

A small, fast desktop app that unlocks with Touch ID, keeps an encrypted offline copy of your vault, and lives in your tray behind a global shortcut. One codebase, every desktop. On Android, the same vault unlocks with your fingerprint.

  • Touch ID & biometric unlock
  • Encrypted offline copy
  • Tray + global shortcut

Download for macOS

Keyfold-macOS-AppleSilicon.dmg

Apple Silicon

Download

Choose your platform

Windows

64-bit

Download

Linux

AppImage

Download

Android

APK · arm64 + armv7

Download

These early builds are not code-signed yet. On first open, macOS users should right-click the app and choose Open; Windows users may see a SmartScreen prompt and can choose More info then Run anyway. The Android APK installs outside the Play Store, so allow the install when your phone asks. iPhone is next.

Keyfold in your browser

Autofill from the extension.

One build serves Chrome and Edge. It detects your browser automatically and stays zero-knowledge, so nothing is decrypted outside your session.

Chrome

Chrome Web Store

Download for Chrome

Unpacked build: unzip, then load it via chrome://extensions (Developer mode). Coming to the Chrome Web Store soon.

Microsoft Edge

Edge Add-ons

Download for Microsoft Edge

Unpacked build: unzip, then load it via edge://extensions (Developer mode). Coming to the Edge Add-ons soon.

Keyfold Send

Share a secret with a link that burns after reading.

Send a password, an API key, or a private note as a single-use link. The secret is encrypted in your browser, and the key that opens it rides in the link fragment, which never reaches our server.

Add a passphrase you share on a different channel, and both the link and the passphrase are needed to open. Once it is viewed once, it is gone.

A one-time link

https://app.keyfold.co.zw/s/a8f2c091#k=Zx9-Qw3rT7uP-••••

Server sees this

/s/a8f2c091, an opaque encrypted blob

Stays in the fragment (#)

the key that decrypts it, never transmitted

  • Encrypted in your browser, then shared.
  • Opened exactly once by the recipient.
  • Destroyed the moment it is read, or when it expires.
For teamsAvailable now

Built for your business, not just your browser.

The same zero-knowledge core scales to organizations. Lioncap, Avalon, ShonaTech, and client tenants each get shared vaults and org recovery, without the server ever holding a readable key.

Shared vaults

Give a team a vault and share items by wrapping the vault key to each member’s public key. No secret is ever readable in transit.

Roles that make sense

Owner, admin, and member. Invite people, move them between vaults, and revoke access without ever exposing the underlying keys.

Org recovery

Admins hold a recovery key that can restore a staff member’s vault. It is explicit and visible: members can see recovery is enabled.

Visible audit trail

Every auth and vault event is logged so a business tenant can see who did what, and when.

Data sovereignty

Your data stays where you can see it.

Self-hosting a password manager on shared national infrastructure is only acceptable if the host can never read the data. Keyfold is designed for exactly that: sovereign by location, and sovereign by cryptography.

At rest in Zimbabwe, encrypted before it leaves your device.

Hosted in Zimbabwe

Every encrypted vault lives on our own machine in-country. Your data does not cross a border to a cloud you cannot see.

Self-host it yourself

Keyfold is built to run on your own infrastructure. Run the whole stack yourself and answer to no one for where your secrets sit.

End-to-end encrypted

Because encryption happens on your device, hosting on shared infrastructure is safe: whoever holds the disk holds only ciphertext.

Switching overAvailable now

Bring everything with you.

Import your full export from 1Password, Bitwarden, or LastPass. Custom fields and sections come along, so every item lands intact instead of flattened into a note.

1Password
Bitwarden
LastPass
Keyfoldround-trips cleanly

Your secrets, sealed on your terms.

Take your passwords back. Encrypted on your device, hosted in Zimbabwe, readable only by you.