Store data online that only you can read.
Cryple is a zero-knowledge vault for the things you cannot afford to lose: passwords, seed phrases, notes, documents and files. Everything is encrypted in your browser before it is sent, and the keys are derived from a recovery phrase only you hold.
Everything in one vault
Secrets
Notes
Documents
Drive
Safe sharing
Passwords
Why is Cryple Different?
Every vault claims zero-knowledge. Post-quantum is a line on someone's spec sheet. Cryple is all three at once, and it is the combination — not any one of them — that nobody else is shipping.

Zero-Knowledge by Construction, Not by Policy
Every item gets its own random key, generated on your device and wrapped under a key derived from your recovery phrase. What reaches our servers is a sealed blob and the little that routing needs — its size, and when it changed. There is no master key, no recovery database, no support tool that opens your vault. Not because we promise not to look, but because there is nothing on our side to look with.

You Are Not The Product
No ads, no tracking, no cookies. Our free tier is genuinely free, and you pay when you want more room. Zero-knowledge is the architecture, not the marketing: the locks and the keys are made on your device, and we cannot see your passwords, read your notes, or open your files under any circumstances.

Everything You Actually Need to Keep
Small secrets that unlock everything else — seed phrases, account details, credentials. Notes for the things that need explaining. Long-form documents that sync across your devices as you write. Encrypted files are next. One vault, one phrase, every kind of thing you would otherwise scatter across a notes app, a drive and a drawer.

Write on One Device, Read on Any Other
Documents sync as you type, encrypted the whole way. Your devices agree on the text without our servers ever seeing it — they store and forward sealed changes and merge nothing. Open a new browser, type your phrase, and everything is simply there.

What You Get Instead of a Reset
We considered letting trusted contacts hold pieces of your key and decided against it: any door built for you is a door that exists. So we give you the artifact instead — a printable kit at sign-up, and plain words about what you are responsible for, before you are responsible for it.

Your Recovery Phrase Is the Account
Twelve or twenty-four ordinary words, generated in your browser. Every key Cryple uses is derived from them the same way on every device — no email, no password. Type the phrase into a new browser and your vault is simply there. It also means nobody can let you back in, including us: the phrase is the account, so losing it loses everything, which is why we make you verify your copy before you begin.

Paranoid Mode — a 6-Digit PIN as a Second Factor
Both modes use a 6-digit PIN to lock the app and encrypt the copy of your phrase on that device. In Standard mode it stays local — forget it and you sign back in with your phrase, losing nothing. In Paranoid mode the server checks it too, so a stolen phrase alone gets nobody in. That protection is real and so is its cost: a forgotten PIN ends a Paranoid account, and we say so on the screen where you turn it on.

Already Beyond Quantum Reach
Your vault is sealed with AES-256 keyed from your phrase, and symmetric encryption is precisely what survives a quantum computer — Grover's algorithm halves the exponent and nothing more. What a quantum computer does break is public-key cryptography, and that is only needed when two people who share no secret must agree on a key. So the exchange behind private sharing combines a classical algorithm with a post-quantum one, and an attacker has to break both. It is implemented, specified, and machine-checked against fixed test vectors.
Secure Your Early Access
Join our waitlist today and secure your spot in our upcoming releases.
September 2026
Staging Release
Live now: the vault, encrypted notes and long-form documents that sync across devices, in both Standard and Paranoid mode.
Encrypted file storage — images and PDFs. The place for the documents that actually matter: contracts, medical records, passports, IDs. Sealed on your device exactly like everything else. Private sharing follows: send one item to one person, still end-to-end.
December 2026
The Drive
2027
Production Launch
No date yet. The vault opened to everyone.
Join the waitlist to be notified about the official launch. During the first month of release, premium subscriptions will have a 50% discount.
How It Works
You set it up once, in a couple of minutes, and after that it just holds things.
1. Generate Your Recovery Phrase
Open Cryple and your browser generates twelve or twenty-four words, then derives your whole key tree from them locally. Nothing is sent anywhere. Write the phrase down on paper, and choose Standard or Paranoid mode.
2. Fill the Vault
Store the small things that unlock everything else — seed phrases, account details, credentials. Write notes: the letters and instructions that explain them. Write long-form documents that sync across your devices. All of it encrypted here, before it leaves.
3. Open It Anywhere
Your phrase is the account, so a new browser needs nothing else. Type it in and your vault is there, decrypted locally. Set a 6-digit PIN on each device so coming back is six digits rather than twelve words.
4. Put the Phrase Somewhere Real
Print the kit we give you at sign-up, or write the words on paper, and store it where you would keep a passport. This is the one part we cannot do for you, and the one part that matters most: nobody — us included — can issue you another.
Security You Can Verify
Zero-knowledge by construction, not by policy: the server never receives anything readable, because the keys are made on your device and never sent.
- Everything is encrypted in your browser; the server receives sealed data and stores it
- Zero-knowledge by construction — there is no key on our side to decrypt with
- Proof of ownership by ECDSA P-256 signature over a fresh challenge, never a transmitted secret
- Your data at rest is AES-256-GCM — symmetric, and already beyond the reach of a quantum computer
- Hybrid PQXDH for encrypting to another account: X25519 + ML-KEM-768 combined, so a classical and a quantum attack must both succeed
- Paranoid Mode: a real second factor, requiring your recovery phrase and your PIN together
- Your recovery phrase, your PIN and your plaintext never leave your device, ever
- No account recovery of any kind, by design — there is no path back in for us to be compelled to use
Technical Specifications
- Symmetric Encryption: AES-256-GCM
- Classic Key Exchange: X25519 (ECDH)
- Post-Quantum KEM: ML-KEM-768 (FIPS 203) — for sharing
- Hybrid Protocol: PQXDH (X25519 + ML-KEM-768) — for sharing
- Key Derivation: BIP39 → SLIP-0010 P-256
- Authentication: ECDSA P-256 Signatures
- PIN Stretching: PBKDF2-SHA256 (600k) client-side
- Server Hashing: Argon2id (64 MiB, t=3, p=4)