No silent sync
No permanent cloud sync that creates another attack surface.
BlindLock starts with your device, not a provider cloud. The complete password vault stays encrypted inside a PNG carrier and opens only when the file, master password and authorised device match.
No permanent cloud sync that creates another attack surface.
Paid Lifetime covers one active Windows, macOS or Linux device. iOS and Android are always free.
Local use is not a limitation. It is the security decision.
If your top priority is seamless sync across many devices, a cloud manager may be more convenient. BlindLock chooses local control and reduced central attack surface instead.
For BlindLock, local-first is an architecture decision about where the data sits, not a marketing phrase. Your password, note and 2FA entries live inside an encrypted PNG carrier on your device. Larger documents and media use separate disguised, encrypted file-vault containers. BlindLock servers hold no copy, and no automatic vault-sync service moves either storage type.
At rest, the contents stay encrypted. They are decrypted only when you unlock, and only in memory, for as long as the vault is open. Close the app or lock the device and the decrypted state leaves memory again. What remains on disk is the ordinary-looking carrier file, with no fixed BlindLock header or vault marker that advertises the concealed contents.
These terms answer different questions. “Local” describes where vault contents live: on storage you control. “Cloudless” means there is no central customer-vault database or automatic vault sync. “Offline” needs a narrower definition: activation and every new unlock require licence and version checks, while an opened vault continues locally until the session closes.
You open your laptop in the morning and unlock the vault with the carrier file and your password. The device itself is the third factor, anchored through TPM 2.0, Secure Enclave or StrongBox, depending on the platform. While the vault is open you copy a password to the clipboard and read a 2FA code (TOTP, a time-based one-time password).
In the afternoon you lock the vault. The decrypted contents leave memory, and no vault contents have been uploaded to BlindLock. In the evening you back up the carrier and create an encrypted BlindLock backup for migration. You keep the recovery phrase separately.
No. BlindLock operates no central customer-vault database or automatic vault-sync service. The encrypted carrier stays on storage you control unless you deliberately copy or export it.
Only in your device's memory, and only while the vault is open. Once it closes, all that remains on disk is the encrypted file.
Back up the active carrier. For device migration and emergencies, also create an encrypted BlindLock backup and keep the recovery phrase separately. If you use file vaults, back up each container with its recovery file and recovery factor.
“Local” describes where vault contents are stored. “Cloudless” describes the absence of a central customer-vault service. “Offline” does not mean the app never connects: every new unlock needs a licence and version check.
Does this local-first setup fit you? Then claim one of the 1,000 lifetime licences. One licence covers one active device; prices rise in three phases from €59 to €79 to €99, after which the subscription is €4.99 per month or €39.99 per year.