-
The security model
-
Your AI needs access.
Not to everything.
-
A password manager that blocks AI agents is useless in 2025. But one that hands them everything is a liability. vault1984 solves this with two layers.
-
-
-
Sealed fields
-
Only you. Only in person.
-
Passwords and private notes are encrypted on your device with a key derived from your fingerprint or hardware token. We store a locked box. No key ever reaches our servers. Not a court order. Not your AI assistant. Sealed fields require your physical presence to unlock.
-
-
-
Agent fields
-
Your AI, scoped and controlled.
-
Fields you designate as agent-accessible are encrypted on our servers. You issue scoped tokens — Claude gets your GitHub token, nothing else. Revoke at any time. The agent never sees sealed fields, no matter what.
-
-
-
Why Zürich
-
Sealed fields: jurisdiction irrelevant.
Agent fields: it isn't.
-
Sealed fields are protected by math — the server's location doesn't matter. But agent fields live on a server in a jurisdiction. A US server is subject to the CLOUD Act. A UK server to the Investigatory Powers Act. Zürich is subject to Swiss law — which does not cooperate with foreign government data requests. No backdoors. Both layers protected.
-
-
-
Self-hosted · US
-
Your server, your rules — until a court says otherwise. CLOUD Act applies to US persons regardless of encryption.
-
-
-
Self-hosted · anywhere
-
Full control. Your infrastructure, your jurisdiction. The right choice if you know what you're doing.
-
-
-
Hosted · Zürich, Switzerland
-
Swiss law. Swiss courts. No CLOUD Act. No backdoors. We handle the infrastructure — you get the protection.
-
-
-
+
+
The problem
+
Your AI assistant needs your credentials.
That changes everything.
+
A password manager that blocks AI agents is useless in 2025. But one that hands them everything is a liability. The question is: how do you give Claude access to your GitHub token without giving it access to your bank password?
-
-
+
+
+
Sealed fields
+
Only you. Only in person.
+
Passwords and private notes are encrypted on your device with a key derived from your fingerprint or hardware token. We store a locked box. No key ever reaches our servers — not a court order, not your AI assistant. Sealed fields require your physical presence to unlock.
+
+
+
Agent fields
+
Your AI, scoped and controlled.
+
Fields you designate as agent-accessible are encrypted on our servers. You issue scoped tokens — Claude gets your GitHub token, nothing else. Revoke at any time. The agent never touches sealed fields, no matter what.
+
+
+
+
+
Why Zürich
+
Sealed fields: jurisdiction irrelevant.
Agent fields: it isn’t.
+
Sealed fields are protected by math — where the server sits doesn’t matter. But agent fields live on a server in a jurisdiction. A US server is subject to the CLOUD Act. Zürich, Switzerland is subject to Swiss law — which does not cooperate with foreign government data requests. No backdoors. Both layers protected.
+
+
+
Self-hosted · US
+
Your server, your rules — until a court says otherwise. CLOUD Act applies to US persons regardless of encryption.
+
+
+
Self-hosted · anywhere
+
Full control. Your infrastructure, your jurisdiction. The right choice if you know what you’re doing.
+
+
+
Hosted · Zürich, Switzerland
+
Swiss law. Swiss courts. Capital of Privacy. No CLOUD Act. No backdoors. We handle the infrastructure — you get the protection.
+
+
+
+
+