PassStash

Passwords stay encrypted where you use them.

A zero-knowledge vault for Trucell and commercial clients. Devices encrypt before sync — the AU region server never sees your master password or plaintext secrets.

Designed around a hard boundary

PassStash separates client crypto from the sync API on purpose. That boundary is the product promise — not a marketing slogan.

Zero-knowledge sync

Clients derive keys locally and upload opaque envelopes. The API stores, versions, and fans out ciphertext — it cannot decrypt vault items.

Modern client surfaces

A Manifest V3 browser extension is in active development. Desktop and mobile MAUI clients follow once the shared crypto core is complete.

Organisation ready

Shared vaults, recovery workflows, and region-pinned sync are built for MSP and enterprise rollout — starting with Trucell’s own fleet.

What is live today

The AU sync region is hosted on Equinix SY3 behind api.passstash.com. Marketing lives here on apex and www.

  • Argon2id + AES-GCM client crypto with cross-language vectors
  • Sync API, SignalR vault hub, attachments as ciphertext
  • Organisations, rekey, recovery, TOTP 2FA, breach checks

Built to replace Keeper for Trucell work

PassStash is the internal and commercial successor path — same zero-trust expectation, owned stack, AU residency for the first region.