XG8
x-gate.app Our Vibe, Your Fun
ONLINE Open Vault
ZERO-KNOWLEDGE CYBER VAULT — NO RECURRING TRAPS

PassKeeper: Zero-Knowledge Security. Zero Monthly Subscriptions.

The private password vault engineered for privacy purists. Your credentials never touch an unencrypted server—encrypted client-side via native Argon2id key derivation and AES-256-GCM.

100% Offline Capable
Argon2id Key Derivation
Zero Tracking
Gelderland, NL Entity
// UNCOMPROMISING CRYPTOGRAPHIC SPECS

Engineered for Sovereign Password Ownership

Unlike centralized cloud managers that store encrypted blobs on remote databases, PassKeeper isolates your credentials strictly on your device.

Client-Side Cryptography

Master passwords never leave your hardware. Symmetric keys are derived locally in volatile memory with memory-hard Argon2id and authenticated via AES-256-GCM.

No Recurring Traps

Break free from €35/year subscription locks. Own your vault. Enjoy full web vault functionality free forever, with optional one-time device licensing.

Air-Gapped / Offline First

Works flawlessly without an active internet connection. No remote server downtime or authentication lockouts when you need your passwords most.

Biometric & Instant Unlock

Frictionless device authentication with native biometric sensors (fingerprint & face recognition) on Android and WebAuthn hardware keys.

// ARCHITECTURAL SHOWDOWN

Why Privacy Advocates Are Leaving Big Cloud Managers

Compare the fundamental operational realities of XG8 PassKeeper against centralized corporate SaaS utilities.

Capability Big Cloud Managers (1Password, LastPass, Dashlane) XG8 PassKeeper SOVEREIGN
Pricing Model Monthly / Annual Recurring Subscriptions (€35–€70/year indefinitely) Free Web Vault / One-time License (€9.99/yr or Lifetime) — Zero lock-in
Data Exposure Risk High (Centralized databases, cloud breaches, third-party hosting risk) Zero (Air-gapped, encrypted client-side via Argon2id + AES-256-GCM)
Offline Access Often degraded, read-only, or blocked by synchronization auth locks 100% Native Offline Functionality without dependency on remote hosts
Telemetry & Tracking Embedded third-party analytics trackers, session telemetry, user profiling Strict Zero-Telemetry Dutch Privacy Standard (No trackers, no cookies)
// FREQUENTLY ASKED QUESTIONS

Cryptographic Transparency & Security FAQ

Answers to common questions regarding client-side encryption, master key recovery, and credential sovereignty.

How does zero-knowledge encryption protect my master password?
When you unlock PassKeeper, your master password is used locally as the seed for Argon2id (the winning algorithm of the international Password Hashing Competition). It derives a 256-bit symmetric encryption key strictly inside your device's volatile memory. All encryption and decryption operations (AES-256-GCM) execute locally on your processor. Neither your master password, your derivation seed, nor your plaintext credentials are ever sent across the network. If our servers were completely seized, attackers would find zero plaintext credentials or decryption keys.
Can XG8 recover my vault if I lose my master key?
No. True zero-knowledge architecture means zero architectural backdoors. Because XG8 never stores your master password or derivation key, we possess no mathematical ability to decrypt or reset your vault if your credentials and emergency recovery sheet are lost. While this requires personal responsibility, it guarantees that no rogue insider, government subpoena, or cloud data breach can ever compromise your vault.
How do I export or backup my credentials?
PassKeeper provides one-click AES-256 encrypted JSON exports as well as standard unencrypted CSV formats. You can store your encrypted backup file on a physical USB drive, an air-gapped local NAS, or personal storage of your choice. You retain 100% data sovereignty and can migrate or restore your vault on any device at any time.
How does PassKeeper compare to browser-saved passwords (Chrome, Edge, Safari)?
Web browsers store passwords in predictable local database files protected only by basic operating system login credentials. Infostealer malware families (such as RedLine, Vidar, and Lumma) actively scan and extract these browser databases in milliseconds. PassKeeper isolates your credentials in a dedicated encrypted enclave with mandatory biometric or master password re-authentication for every reveal or autofill action.
// SOVEREIGNTY IN 30 SECONDS

Take Back Control of Your Digital Identity

Zero cloud plaintext. Zero subscriptions. Instant web vault access with zero installation required.