bitlock

bitlock://online-vault

Secrets go in. Plaintext does not come out.

BitLock encrypts password, note, crypto-key, and recovery-code content in your browser before syncing it to Turso.

01 / runtime
Your browser
The master password stays here
02 / cipher
AES-256-GCM
PBKDF2 · 600 000
03 / storage
Turso · libSQL
Secure libSQL synchronization

Workflow / 4 stages

From raw secret to verifiable vault.

Every stage maps to a real app feature. No third-party cloud, no marketing telemetry, and no vague claims.

  1. 1.0

    Capture

    Add a link, credential, crypto key, or recovery-code file.

    Open the vault
  2. 2.0

    Encrypt

    AES-256-GCM protects content before storage. PBKDF2 derives the key from your master password.

    Read the model
  3. 3.0

    Find

    Search, type filters, and favorites keep a full vault usable without exposing its secrets.

    See organization
  4. 4.0

    Audit

    The audit inspects metadata, duplicates, and stale entries without decrypting sensitive content.

    Run the audit

Data types / index

One vault, six focused capabilities.

Each secret type gets its own workflow while sharing one encryption model and search layer.

Local utilities / no account

Generate and verify before storing.

Data path / zero knowledge

The server never receives the key.

The master password lives in browser-session memory. Storage receives a salt, initialization vector, and encrypted payload — not a readable secret.

Inspect the audit module
  1. A
    Secret in memoryEntered in the browser
  2. B
    Local encryptionAES-256-GCM + PBKDF2 key
  3. C
    Protected payloadSynchronized to Turso

FAQ / 04

Frequently Asked Questions

Is BitLock really free?

Yes. Core vault features, the basic tools, and standard storage remain free. The goal is to make serious security accessible without a forced subscription.

How does zero-knowledge encryption work?

Secret content is encrypted in your browser with your master password before it is sent. The server also stores the account and vault metadata required to operate the service, but receives neither the key nor secret content in plaintext.

What happens if I forget my master password?

Due to zero-knowledge encryption, we cannot recover your master password or your encrypted data. That's why it's essential to memorize it or keep it in a safe place.

What happens if the local database is copied?

Encrypted content remains unreadable without the master password. Account and vault metadata remains visible, and a compromised device during an unlocked session should be treated as exposed.

Create the vault. Keep the key.

Create my vault