Medel VaultMedel Vault
login Sign in
Zero-knowledge vault · start free

Your passwords, encrypted in a vault only you can open.

AES-256 with a key derived from your PIN via PBKDF2 (200,000 iterations). Passwords, cards, notes, files and 2FA — every secret encrypted on your device. Without your PIN, neither we nor anyone else can decrypt your data.

login Sign in
  • check_circle Free to start
  • check_circle No credit card
  • check_circle End-to-end encrypted
  • check_circle Installable PWA
Everything in one vault

More than a password manager.

A single vault for your logins, your 2FA, your cards, your sensitive files — and who gets access if something happens to you.

vpn_key

PIN-derived encryption

Your vault key is derived from a 4-digit PIN with PBKDF2-SHA256 at 200,000 iterations. Without your PIN, the data in the database is noise.

enhanced_encryption

Per-item envelope encryption

Every password, card or note has its own key wrapped with your vault key. A server leak exposes nothing in clear.

qr_code_2

Built-in 2FA authenticator

Generate and store TOTP codes by scanning a QR. Replaces Google Authenticator and you never lose your codes when changing phones.

group

Emergency contacts

Up to 5 trusted people can request access to your vault. With a configurable waiting period (e.g. 7 days) so you can deny.

crisis_alert

Breach alerts

We cross-check your passwords against public breach databases. We email you if any appears. On Pro, in real time.

folder_zip

Encrypted files

Store PDFs, deeds, ID photos or sensitive backups. All encrypted with the same vault key. Your Drive stays yours.

notifications_active

Login alerts

Instant email every time your vault is unlocked: IP, location, browser. Recognise the access — or cut it off in one click.

devices_other

Log out on every device

Lost your phone? One click and every active session is invalidated instantly. Your encrypted cookies stop working.

restore

Recovery code

When you create the PIN we give you a unique code. If you forget the PIN, you use it to unlock without losing a single data point. Print it and keep it safe.

password

Cryptographic generator

Passwords and passphrases with real randomness from the browser. Works offline. Your preferences stay local.

phonelink

Installable PWA

iOS, Android, Windows, macOS, Linux. Once installed it feels like a native app — no browser chrome.

login

Passwordless login

Sign in with Google, Apple or a 6-digit email code. One less layer to remember, one less layer to leak.

How it works

Your PIN never reaches the server. Your vault key never reaches the log.

  • enhanced_encryption
    Per-item envelope encryption

    Each password, card or note has its own encryption key, wrapped with your vault key. A hypothetical DB leak exposes nothing in clear.

  • key
    Bcrypt (cost 11) for the PIN

    The PIN is hashed before storage. Even if someone accesses the DB, they cannot recover your PIN or brute-force it in reasonable time.

  • timer
    Rate limit and blocks

    5 failed attempts per minute per IP+user. Online brute force gives up before it starts.

  • cookie
    AES-256-GCM cookies

    Your persistent session cookie is encrypted and signed. Stealing it does not open your vault — your PIN is still required.

Who it is for

One vault. Every life fits inside.

person

For you

Centralise every personal login — from Netflix to your bank — and stop reusing passwords. Generator and 2FA in the same place.

family_restroom

For your family

Designate your partner, parents or siblings as emergency contacts. If something happens to you they can access after the waiting period you set.

business_center

For freelancers

Client logins, API keys, company cards, IBAN and invoices — all in one vault. No more WhatsApp shares or iCloud notes.

groups

For small teams

Each member with their own vault and cross-custody via emergency contacts. No admin panels that invite disaster.

What you can store

One vault. Five kinds of secret.

vpn_key

Passwords

With icon, autofill, built-in generator and breach check.

qr_code_2

2FA codes

Scan a QR and store the TOTP secret. Replaces Google Authenticator.

credit_card

Cards

Number, expiry, CVC and holder. Encrypted the same as passwords.

account_balance

Bank accounts

IBAN, holder, ID, branch phone. No more Google Drive.

edit_note

Notes and files

Rich text and documents. Mark any item as secret.

Simple plans, zero surprises

Start free. Upgrade when you need to. Cancel anytime.

Basic

Start protecting your passwords safely and easily

Free forever
  • check Up to 50 passwords ?
  • check 2 devices at the same time ?
  • check 2 security scans per month ?
  • check 10 MB for encrypted documents ?
  • close No leak alerts ?
  • close No emergency contacts ?
person_add Start free
★ Most popular

Secure

Complete protection for your digital life on all your devices

3,49 € /mo
or 34,99 € per year
  • check Unlimited passwords ?
  • check Unlimited devices ?
  • check Basic leak alerts ?
  • check Unlimited security scans (no history) ?
  • check Monthly security report ?
  • check 1 emergency contact ?
  • check 100 MB of document storage ?

Advanced

Total control and advanced protection of your digital security

6,99 € /mo
or 69,99 € per year
  • check Unlimited passwords ?
  • check Unlimited devices
  • check Real-time leak alerts ?
  • check Complete scan history ?
  • check 5 emergency contacts ?
  • check Unlimited monthly scans ?
  • check Monthly Security Summary
  • check 500 MB for encrypted documents

Secure payments · Cancel anytime · No commitments

What people say

They trust us to protect their day-to-day.

star star star star star

After years using 1Password I switched to Medel Vault and I don't miss anything. Zero-knowledge encryption gives me the peace of mind I need, and the interface is much cleaner.

María González UX Designer, Freelance
star star star star star

The password generator and anti-HIBP scan are just what my team needed. I recommend it to all devs.

Carlos Ruiz CTO, Stackmint
star star star star star

Finally a manager I understand. The 4-digit PIN makes opening the vault a snap and the emergency contacts give me peace of mind.

Lucía Pérez Journalist
Frequently asked questions

What you keep asking us.

Sign in with Google, Apple, or an email code and create a 4-digit PIN. That PIN encrypts your data: no one else, not even us, can decrypt it without it. After creating it you will receive a recovery code that you must save in a safe place.
Your vault key is derived from the PIN with PBKDF2-SHA256 at 200,000 iterations and encrypts each item with AES-256 (envelope encryption per item). Session cookies use AES-256-GCM and the PIN is hashed with bcrypt cost 11. It's zero-knowledge: if our server went down tomorrow, the data in the database would still be noise without your PIN.
You have two ways: (1) use the recovery code that you saved when creating the PIN — it unlocks the vault and lets you create a new PIN without losing data. (2) Request a reset from the PIN screen; You will receive an email with a link that delete your encrypted data. This is what makes encryption truly secure: not even we can recover them without your PIN or code.
Five types of secrets, all encrypted with the same vault key: passwords (with icon and autocomplete), 2FA codes (TOTP), cards (number, expiration, CVC, holder), bank accounts (IBAN, ID, branch) and notes and files (rich text and sensitive documents such as PDFs or photos of the ID).
Yes. You scan the QR of any service and save the TOTP secret in your vault. The app generates 6-digit codes every 30 seconds, and when you change your phone you do not lose anything — just enter and see your codes again.
Up to 5 trusted people whom you authorize to request access to your vault. When you request it, a configurable wait begins (by default 7 days) during which you receive notifications and can deny it. If you do not respond, the contact agrees at the end of the period. Designed for when something happens to you — not for day-to-day shared use.
Yes. We cross-check your passwords against public leak databases (HIBP) without ever sending the password in the clear — we use the k-anonymity model. If any appear, we will notify you by email so you can change it. In the Pro plan, the checks are in real time.
You start free, without a card — includes 50 items, 5 MB of files and 2 scans per month. Premium and Pro plans unlock unlimited vault, large archives, breach alerts, emergency contacts and unlimited scans. You can cancel whenever you want; It is not renewed without notice.

Start in 30 seconds.

Free trial across every plan. No credit card.

login Sign in