Honest comparison · Apex is in development
Apex Password vs KeePassXC
KeePassXC is the closest philosophical relative to Apex in this list. It is free, open source, and fully local: your passwords live in an encrypted .kdbx database file on your own disk, and no server is involved unless you add one.
At a glance
§ Side by side| Apex Password | KeePassXC | |
|---|---|---|
| Where the vault lives | On your phone, next to the secure enclave and biometrics | In a .kdbx file on your computer (or wherever you put it) |
| If malware hits your computer | Vault is never on the computer; with Apex Agent, SSH/GPG keys aren’t either. An info-stealer finds no vault file and no keys to copy - at most the single credential in active use. | The .kdbx file sits on disk and is decrypted in memory when unlocked; an info-stealer can copy it and keylog the password. The built-in SSH agent keeps keys on the desktop, within reach of the same malware. |
| Open source | MIT license; full repository opens at launch | Yes - GPL, long-established community project |
| Server involved | Optional content-blind relay for cross-network requests; LAN and offline work without it | None at all |
| Multi-device sync | No vault sync; devices pair and exchange single credentials end-to-end encrypted | DIY - you sync the database file yourself (cloud drive, Syncthing, USB, …) |
| Browser autofill | Extension asks your phone; you approve each login biometrically | KeePassXC-Browser fills from the unlocked database on the same machine |
| Mobile | The phone app is the product’s core | Via third-party compatible apps |
| SSH keys | Apex Agent (coming soon) keeps SSH/GPG keys on the phone with per-use approval | Built-in SSH agent holds keys on the desktop |
| Independent audits | Not yet independently audited; built on standard primitives (AES-256-GCM, P-256, Argon2id) | Mature codebase; has received third-party review over its lifetime |
| Maturity | In development - launching in stages (mobile app and relay first) | Shipped, stable, battle-tested |
Comparison reflects each product's publicly documented architecture and may change as products evolve. Found something inaccurate? Tell us and we'll fix it.
The differences are about workflow, not philosophy. KeePassXC is anchored to the desktop: the database file lives on your computer, browser integration unlocks it there, and getting it onto a phone means syncing the file yourself and using a compatible third-party app. Apex is anchored to the phone: the vault lives next to the secure enclave and biometrics, and the desktop never holds it - it requests one credential at a time, approved on the phone.
If you already run a disciplined KeePassXC setup, Apex’s pitch is mostly about multi-device ergonomics: pairing by QR code, per-login biometric approval, and an end-to-end encrypted relay instead of hand-rolled file sync.
Which should you pick?
§ Trade-offsChoose KeePassXC if…
- You want a fully offline, file-based vault you control byte-for-byte, today.
- You are comfortable managing your own file sync and backups.
- You work primarily on one desktop and rarely need credentials elsewhere.
- You want zero infrastructure - not even a content-blind relay.
Choose Apex if…
- You like the local-first philosophy but want the phone - with its secure enclave and biometrics - as the anchor instead of a desktop file.
- You want per-login approval on a separate device, so a compromised desktop can’t read your whole database.
- You want multi-device access without hand-managing .kdbx sync conflicts.
- You want SSH/GPG signing where the key never touches the laptop.
Bottom line: KeePassXC and Apex agree on the core idea: your vault should be yours, locally. KeePassXC delivers that today in a desktop-file form. Apex re-centers it on the phone and adds an approval flow between devices. Many KeePassXC users will be the first people Apex makes sense to.
Common questions
§ FAQIsn’t KeePassXC already "local-first"? What does Apex add?
Yes, KeePassXC is genuinely local-first. Apex differs in where the trust anchor sits and how other devices get credentials: the vault lives on a biometric-locked phone, and desktops receive exactly one credential per approved request instead of unlocking the whole database locally.
KeePassXC needs no server at all - doesn’t Apex’s relay add risk?
The relay only routes end-to-end encrypted payloads and is optional: on the same network, devices can talk over LAN, and the vault itself works fully offline. The relay never holds vaults or keys, and you can self-host it. It buys cross-network convenience at the cost of (encrypted) traffic metadata - we say so plainly.
Which should I use today?
Today: KeePassXC (or another shipped manager) - Apex is still in development. If Apex’s phone-anchored model appeals to you, join the launch list and switch when it ships.
§ Get the suite
Your secrets, your device, your rules.
Apex is launching in stages. The mobile app and the relay are first. The browser extension and desktop agent follow.
No tracking pixels. No newsletter blast. One email when the apps ship.