Track transactions, banks, cards, passwords and documents. AES-256-GCM encrypted with your PIN — stored only on your device. No accounts. Optional E2E encrypted cloud sync for multi-device use.
In its default state, GoVault makes zero network requests. Your financial data, passwords, and documents are encrypted with AES-256-GCM and stored exclusively in your browser's localStorage. No server receives anything. No analytics. No telemetry. Not even an error log reaches the outside world.
GoVault is not a web app that stores your data somewhere safer. It is the safe — running entirely inside your browser, with no external dependencies.
GoVault uses the WebCrypto API — the same browser-native cryptography used by banks. No third-party crypto libraries.
| Algorithm | AES-256-GCM (Galois/Counter Mode) |
| Key Length | 256 bits |
| Key Derivation | PBKDF2 + SHA-256 |
| Iterations | 200,000 |
| Salt | Random 128-bit, stored with ciphertext |
| IV / Nonce | Random 96-bit per write operation |
| PIN Storage | Session memory only — never written to disk |
| Network Calls | None in local mode · sync endpoint only when cloud sync is enabled |
| Cloud Storage | None in local mode · optional E2E encrypted sync (Neon PostgreSQL, Singapore) |
| Cloud Sync | Opt-in · AES-256-GCM encrypted before leaving device · server sees ciphertext only |
| Fully Secure Mode | In-app toggle that disables all network activity — zero-network, air-gapped vault |
| Default Network Calls | None — zero requests in local mode; sync endpoint only when cloud sync is explicitly enabled |
Six purpose-built modules for your complete financial picture. All encrypted. All local.
No onboarding flow. No email. No cloud sync. Open the file, set a PIN, and your encrypted vault is ready in seconds.