Zero-knowledge by design

Your secrets.
Yours alone.

Fratera NullKey brings passwords, API keys, authenticator codes, secure notes, photos, and videos together in one encrypted vault.

All vaults Encrypted
Production API
••••••••••••PROD
Database credentials
••••••••••••SERVER
Two-factor code
482 90124 SEC
Private media
Photos & videosAES-256
Everything sensitive, organized

More than a password manager.

NullKey is built for people who manage more than logins. Keep personal credentials, developer secrets, private notes, and encrypted media structured without giving the service readable access to their contents.

01 / VAULTS

Passwords and secrets

Store logins, API keys, servers, databases, cards, identities, wallets, and general secrets with folders, project organization, environment labels, filters, and search.

02 / AUTH

Built-in authenticator

Generate TOTP one-time codes beside the accounts they protect. Add compatible details directly or import supported authenticator QR codes.

03 / AUTOFILL

Password AutoFill

Fill normal login entries in Safari, other browsers, and apps through the iOS Password AutoFill provider. Hidden and decoy items remain excluded.

04 / MEDIA

Encrypted media

Organize private photos and videos in encrypted folders with thumbnails, playback, export, and authenticated chunked video streaming.

05 / OFFLINE

Available offline

An encrypted local cache keeps your vault useful without a connection. Queued changes synchronize after reconnecting with conflict preservation.

06 / TOOLS

Security tools

Create strong passwords and run a local-only audit for weak, reused, or missing passwords, URL health, and saved two-factor status.

07 / NOTES

Secure notes

Keep encrypted notes and color-coded stickies inside organized Notes Pages, with Quick Notes providing a single accumulation view.

08 / HIDDEN

Hidden and decoy vaults

A separately keyed Hidden Vault protects especially sensitive data. An optional device-local decoy vault can support a lockdown response.

09 / RECOVERY

Recovery designed in

A Recovery Key and printable Emergency Kit can restore the main vault. Hidden Vault data intentionally uses a separate recovery model.

Security model

Encrypted before it leaves your device.

NullKey is designed so the backend stores encrypted vault data rather than readable secrets. Your Decryption Key is not uploaded to the service.

Cryptography: AES-256-GCM protects vault records and media. PBKDF2-HMAC-SHA-256, Argon2id, HKDF-SHA-256, and standard HMAC algorithms support key derivation, local unlock, recovery, and TOTP generation.

Client-side encryption

Vault contents, folder names, notes, and media are encrypted locally before synchronization. The service operator cannot derive the plaintext Vault Key from stored data.

Wrapped-key architecture

A random Vault Key encrypts your data. Your Decryption Key, Recovery Key, and supported device-unlock mechanisms wrap that key for their respective use cases.

Protected quick access

Quick Unlock uses encrypted local key material with platform protections such as Apple Keychain, Secure Enclave where available, and Face ID or Touch ID.

Privacy on the device

Configurable idle locking, background locking, reveal timeouts, clipboard clearing, and an app-switcher privacy shield reduce accidental exposure.

Separate sensitive spaces

The Hidden Vault uses its own random key, while decoy data remains independently encrypted and device-local. Normal, hidden, and decoy data are kept apart.

No security theatre

No software can eliminate every risk. Device compromise, weak credentials, lost recovery material, phishing, or insecure exports can still expose data. Keep devices updated and recovery material safe.

Contact Fratera

Questions, requests, or support?

For privacy requests, legal questions, account support, or security reports, contact us by email.

info@fratera.io