Security of your data is our Priority

Enpass is designed to keep your data safe and secure concerning your right to privacy.

AES 256 Encryption

Your data is protected by world’s leading cryptography algorithm

Your data is fully encrypted with 256-bit AES with 100,000 rounds of PBKDF2-HMAC-SHA512 using the peer-reviewed and open-source encryption engine SQLCipher, providing you with advanced protection against brute force and side channel attacks.

We don’t keep your encryption key or its derivative

The key that encrypts your data is derived from your Master Password. Your master password is only recorded in your mind. There is no record of master password or its derivative with us. If you forget your master password, there is no way to recover your data.

Master password not recorded
Enpass cloud Sync

Sync your data with your preferred cloud provider

Optionally, you can sync your data (AES-256 encrypted) across multiple devices seamlessly through any of supported clouds such as iCloud, Dropbox, Google Drive, OneDrive and WebDAV. Your data is always transmitted in encrypted format. Encryption and decryption always happen locally on the device.

We never keep your data on our servers

We do not save your Enpass data on our servers. Your data is only stored on your device. If you prefer to sync your data between devices, you can use your preferred cloud storage, such as iCloud, Dropbox, Google Drive, OneDrive and WebDAV.

Enpass Sign Up

Frequently Asked Questions

100% of your data is encrypted with Enpass everywhere. You can open data file inside a binary editor and see it yourself. All you will see is nonsense, gibberish data ( encrypted with AES 256). For more information on Enpass security, check out the Enpass Security White Paper.

If you forget your master password nothing can be done to recover it. There are no such backdoor with options to get back or reset your master password as there is no record of it with us. This is the only way we can make the data inaccessible to anyone except you.

Your cloud always contains a copy of same encrypted data as on your device. We download the whole encrypted copy and decrypt it locally on your device for real sync operation to merge changes. Afterwards we upload the encrypted data on cloud. In a nutshell, your cloud is only a storage medium and no security related operation ( encryption or decryption ) is actually performed there. All such operations are performed locally on your device.

Your data is encrypted using the same standard as on your device, i.e. AES-256 with 100,000 rounds of PBKDF2-HMAC-SHA512 using SQLCipher engine. Even if an attacker gains access to your Enpass data file, it is unusable for him until your master password itself is compromised; otherwise it will take him years to crack and peep through your data.

Enpass uses SQLCipher as cryptography engine which is used world wide for cryptographic operations. It is peer reviewed and open-source. Its design details are available here.

Your Enpass data can only be decrypted by your master password. Please read more here to learn how we have used Fingerprint to unlock Enpass with best possible security.

Your Enpass data can only be decrypted by your master password. Please read more here to learn how we have used Touch ID to unlock Enpass with best possible security.

If you have discovered a potential security issue with Enpass, we kindly ask you to go to this page right now..