Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Security model

The vault is encrypted at rest with SQLCipher. A master password is processed locally with Argon2id; the derived key is not written to disk and is cleared when the vault is locked. The database salt is required to recover a vault, so backups must keep it with the encrypted database.

unv defaults to redacted output. Commands that would expose stored values on stdout require an explicit reveal option; use file output or unv exec when a consumer needs a real secret. The optional server supports TLS pinning, scoped users, and compare-and-swap writes to avoid silent overwrite conflicts.

No security control removes the need to protect an unlocked desktop session or the machine on which it runs. Report vulnerabilities through the repository's security policy.