End-to-end encrypted · Local first · MIT licensed

Trust your phone,
not your laptop.

Your phone has a secure enclave, biometric locks, and lives in your pocket. Your laptop runs a hundred processes you didn't write and gets plugged into things. So the vault stays on the phone. When the browser needs a login, it asks; you approve with a fingerprint; one credential is delivered end-to-end encrypted, used once, and discarded. The laptop never holds the vault - only the single password it needs, for the moment it needs it.

MIT · Source opens at launch AES-256-GCM · P-256 · Argon2id

Standard primitives. Auditable code. No proprietary crypto.

  • AES-256-GCM Symmetric encryption
  • P-256 ECDH Key exchange
  • ECDSA P-256 Message signing
  • Argon2id Master-key derivation
  • Content-blind relay Sees ciphertext only
  • MIT licensed Code opening soon

What a password manager looks like when nobody else holds your vault.

§ Capabilities
01

Local-first vault

Passwords, keys, and TOTP secrets - encrypted on your device with an Argon2id-derived key. No account. No cloud sync. Nothing to breach on someone else's server.

storage://encrypted/vault.bin
02

One credential, one moment

The extension requests a single login - never the vault. You approve on-device. The credential is encrypted to that browser tab, decrypted in memory, fills the field, and is wiped on submit.

POST /req → tap to approve
03

Content-blind relay

Devices speak in ciphertext. The relay routes opaque payloads and discards them on delivery - it can't read your data. Self-host the Docker image or use ours.

relay.apexpassword.com
04

Works offline. Pairs air-gapped.

The vault opens with no network at all. Devices pair by scanning a QR code - no server hand-off, no account, no leaked email. The relay is only needed when your browser asks the phone for a credential from somewhere else.

pair via QR · vault opens offline
05

Sign on the phone, work on the laptop

Apex Agent speaks the SSH and GPG agent protocols on your desktop, but the keys live exclusively on your phone. Each git push, ssh, or gpg --sign triggers a tap-to-approve. The signature returns; the key never moves.

ssh → apex-agent → phone
06

Auditable by design

Built on named, standard primitives. MIT-licensed. The full source repository opens at launch - every claim on this page will map to a file you can read.

github.com/apex/* · opening soon

Three hops. None readable.

§ Request flow
  1. 01

    Phone holds the vault

    Master phrase derives a key on-device via Argon2id. The vault is sealed with AES-256-GCM. The key lives in memory only while the vault is unlocked.

  2. 02

    Browser asks. Relay forwards.

    The Portal extension detects a login form and sends a request - encrypted to your phone's public key. Relay routes the opaque payload.

  3. 03

    You approve. The form fills.

    Your phone surfaces the request. Biometric approval. The credential travels back encrypted, decrypts in the browser, fills the field, and is wiped.

See it actually work.

§ Live walkthrough

Click Sign in with Apex to begin.

Assume the laptop is already compromised.

§ The threat model

A malicious npm or PyPI package. A trojaned installer. An info-stealer in a cracked app. Supply-chain attacks have become routine, and they all share one move: code runs with your privileges and vacuums up every secret it can reach before you ever notice. The question stopped being if a dev machine gets popped. It's what the attacker walks away with.

A typical info-stealer haul

On a normal machine

  • Browser-saved passwords & session cookies
  • ~/.ssh private keys (id_ed25519, id_rsa)
  • ~/.gnupg signing & encryption keys
  • .env files, ~/.aws/credentials, cloud tokens
  • Password-manager vault file + unlocked session
  • .npmrc / registry tokens, keychain exports
One compromise becomes account takeover everywhere - and a key to sign code as you.
The same malware, on an Apex machine

Nothing worth taking

  • No vault. It lives on your phone. There is no file to copy and no master password to keylog.
  • No SSH or GPG keys. They never leave the phone - so ~/.ssh and ~/.gnupg hold nothing.
  • No browser password store. The extension holds at most one credential, in memory, for one submission - then wipes it.
The blast radius shrinks from "everything" to, at worst, the single login you happened to be using.
§ The developer angle

Your signing keys can't leak from a machine that never holds them.

A stolen SSH key lets an attacker log into your servers. A stolen GPG or commit-signing key lets them push malicious code under your name and sign a release the world trusts. That's how one compromised laptop turns into the next supply-chain attack. Apex Agent (coming soon) speaks the SSH and GPG agent protocols on your desktop while the private keys stay on your phone. Each git push, ssh, or gpg --sign forwards to the phone for a biometric tap; only the signature comes back. The same agent backs apex run: a project's .env can hold apex://project/KEY references in place of real values, fetched from the phone — with a tap — only for the lifetime of that one command.

  • The key itself is never on disk to exfiltrate.
  • Every signature needs a tap on the phone - malware can't sign or push silently in the background.
  • Revoke a compromised laptop by un-pairing it; the keys were never on it.

The honest scope: Apex removes your highest-value, longest-lived secrets - the password vault and your SSH/GPG keys - from the laptop entirely, and apex run keeps real .env values on the phone, released per command behind a tap. But an env value, unlike a key, has to materialize in the process that uses it: once you approve a run, malware active at that moment can read it from the running command. Source you keep on the machine and any secret in active use are still yours to defend. We move the crown jewels out of reach; we don't claim to make a compromised machine safe.

§ Cryptography

Audit the code.
Trust the math.

No proprietary protocols. No closed black boxes. No "we promise we won't peek." Apex is built on primitives the cryptographic community already trusts - and the full source opens at launch, so every claim can be verified.

  • Master phrase, never transmitted

    Your master phrase derives an Argon2id key locally. The key never leaves your device. Apex has nothing to leak because Apex never receives it.

  • P-256 ECDH between devices

    Devices pair by exchanging P-256 public keys. Every payload uses a fresh ECDH-derived AES-256-GCM key, so the relay only ever sees ciphertext.

  • Signed and authenticated

    Every payload carries an ECDSA P-256 signature. Tampered or replayed messages are rejected before decryption. The relay can't spoof a request.

  • No silent backups, no escrow

    We never hold a recoverable copy of your vault. The only backup is one you create yourself - exported and stored offline (see the Cold Vault Protocol). Lose both your phrase and your backup, and the vault is gone.

Questions, answered honestly.

§ FAQ
  • It will be, fully. Every component - mobile app, browser extension, relay server, desktop agent - is MIT-licensed, and the complete repository goes public at launch. Until then the cryptographic design is documented on this site; nothing in the security model depends on the code staying private.

  • On your phone. The vault is encrypted with AES-256-GCM using a key derived from your master phrase via Argon2id. It never leaves the device in plaintext, and there is no cloud account behind it.

  • We don't - and that's deliberate. The Apex relay never sees your passwords or vault contents (they are end-to-end encrypted between your devices), but it does observe metadata: which devices connect, when, and roughly how large each ciphertext is. Calling that "zero-knowledge" would overstate it. We say "end-to-end encrypted" and "content-blind relay" because those are accurate.

  • Yes. Apex Relay is built for self-hosting and ships as a Docker image at launch. Point your devices at your own instance and you don't have to trust ours - or anyone's - for routing. Both modes are content-blind by construction.

  • Yes. The vault opens without internet. Browser autofill works over local LAN when both devices are on the same network, so airplane mode and dead Wi-Fi don't block you.

  • Without a backup, the vault is gone - there is no escrow and no backdoor. If we could recover it, so could anyone who compromised us. You can opt in to an encrypted backup (see the Cold Vault Protocol) and store it wherever you want; we never hold one for you by default.

  • Those services keep an encrypted blob of your vault on their servers by default. Even with strong encryption, a breach puts that blob in attackers' hands to grind on offline. Apex doesn't upload your vault at all - backups are optional, encrypted client-side, and stored only where you choose. The trade-off: pairing and recovery are your responsibility, not a cloud account's.

  • It removes the most valuable targets from reach. Malware that lands on your computer - a malicious npm/PyPI package, a trojaned app, an info-stealer - runs with your privileges and copies whatever it can find: browser-saved passwords, SSH and GPG keys, .env files, and password-manager vault files. With Apex, the vault is never on the computer and (with Apex Agent) neither are your SSH/GPG keys, so there is no vault file to copy and no master password to keylog. The worst case shrinks from "the attacker has everything" to "the attacker may have seen the one credential you were actively using." We don't claim to make a compromised machine safe - other local secrets you keep there are still yours to defend - but your crown-jewel secrets aren't there to steal.

  • Apex Portal detects a login form and sends an encrypted request to your phone. You approve with biometrics. One credential travels back end-to-end encrypted, decrypts in the browser tab's memory, fills the field, and is wiped on submit. The browser never holds your vault.

  • That's what Apex Agent (coming soon) is for. It speaks the SSH and GPG agent protocols on your desktop, but the private keys live exclusively on your phone - never written to ~/.ssh or ~/.gnupg. Every signature requires a biometric tap, so a stolen or compromised laptop can't exfiltrate your keys, can't push to GitHub as you, can't sign a release, and can't log into your servers. Revoke a lost machine by un-pairing it; the keys were never on it.

§ Get the suite

Your secrets, your device, your rules.

Apex is launching in stages. The mobile app and the relay are first. The browser extension and desktop agent follow.

No tracking pixels. No newsletter blast. One email when the apps ship.