Security

Security is our first priority. Responsible disclosure is welcome.

How UniPass protects your data

Threat model

Threats we defend against

Threats we cannot defend against

Reporting a vulnerability

Please do not report security issues through public GitLab/GitHub issues. Disclose privately:

Our commitment

FAQ

What if I forget my master password?

We cannot retrieve your existing master password. If you enabled a Recovery Code before losing access, that code can re-wrap the same local encryption keys under a new master password and Secret Key, preserving the encrypted vault. We never receive the Recovery Code or plaintext keys.

Without a valid Recovery Code, the email reset flow creates a new encryption identity and an empty vault. It permanently deletes the old encrypted vault and related server-side data; 2FA is still required when enabled. Neither UniPass nor support can decrypt or restore the deleted data.

Do you collect usage data?

No telemetry, crash reports, or usage analytics. With cloud sync enabled we store vault ciphertext and sync metadata (account email, device identifiers, version numbers); nothing else is uploaded. See our Privacy Policy.