Passwords security model

Your vault.
Its protection.

How Trayzen Passwords protects the vault, handles encrypted sync and backups, and what its protection does and does not cover.

Upcoming Windows release · Updated 5 September 2026

01

Master-password protection

Trayzen protects its local password vault and recovery checkpoint with authenticated AES-256-GCM encryption. A random 256-bit data key is protected using a key derived from your master password with Argon2id, 64 MiB of memory, three passes, and a random salt. Trayzen does not store your master password.

Older PBKDF2 vault envelopes are upgraded after a successful unlock. The encryption format described here is the format used for new vaults in the upcoming release.

02

Windows verification

Trayzen uses Windows user verification before sensitive actions. Master-password protection and Windows verification are separate parts of the security model. A Windows verification prompt is not a substitute for keeping your master password and backups safe.

03

Optional encrypted sync

After you connect your Microsoft account and enable sync, Notes and password records are encrypted on your device with a key derived from a separate sync password before they are placed in Trayzen’s private OneDrive app folder. Password records are processed for sync only while the vault is unlocked.

The sync password is protected locally for the current Windows user and is never uploaded. Neither Trayzen nor Microsoft can recover it. Microsoft can observe normal account and transfer metadata, including app-folder file names, sizes, and modification times. Conflicting edits are retained as labelled copies.

Windows-owned passkeys and their private keys are excluded from logical sync. Disconnecting a device stops its connection and clears its locally stored sync password and account choice; existing OneDrive files remain until you remove them.

04

Backups and recovery

You can create a passphrase-protected .trayzenvault backup. Trayzen cannot recover a forgotten master password, backup passphrase, or sync password. Keep the credentials needed for recovery somewhere you can access independently of this vault.

With a valid encrypted backup and its passphrase, you can restore the saved contents under a new master password after Windows verification and confirmation that the current local vault will be replaced. Changes made after that backup will not be present in it.

A user-selected portable backup is not uploaded automatically. The separate, optional OneDrive cloud-backup feature copies the already encrypted local vault file. Keep the corresponding master password: the separate sync password does not replace the password needed to open that vault copy.

05

Clipboard and locking

Credential copies ask Windows to exclude them from clipboard history and roaming. While Trayzen remains running, it attempts to clear its own copied credentials after their timeout. Clearing is best effort and cannot be guaranteed after forced termination, power loss, or interference from another application.

The vault locks after inactivity and responds to supported Windows lock, sign-out, session-disconnect, and suspend events. Lock the vault before leaving the PC unattended.

06

Windows-owned passkeys

On supported Windows versions, Trayzen can display Windows-owned passkey metadata and request removal of credentials Windows marks as removable. Removal requires your confirmation and Windows user verification.

Windows and the authenticator retain the private keys. Trayzen does not create, use, autofill, import, export, or sync these passkeys. The live inventory is not stored as password records in the Trayzen vault.

07

Limits of protection

Encryption does not protect an unlocked vault from malware controlling your Windows session, a keylogger, an administrator, or physical observation. Decrypted information and the data key exist in application memory while the vault is unlocked.

Deleting a record cannot erase separately copied backups, storage snapshots, or other historical copies. A person with a usable older backup and its passphrase may still be able to read the data in that backup.

Questions about this model: hello@trayzen.app.

Privacy policy · Sync & backup setup