Open Source · Rust · Local-First

Your Key.
Your Rules.
Everywhere.

The first open-source security ecosystem that belongs to you – not a cloud, not a corporation. A password manager with a single, auditable Rust core.

🔒 bank.example.de/login
PluriKey
B
📋
G
📋
🔎 Search
⚙ Generator
📁 Vault
100%
Open Source
0
Cloud Dependency
5
Platforms
Rust
One Secure Core

Why Existing Solutions
Fall Short

Your passwords sit in foreign clouds. 2FA is so annoying that you turn it off. And AI generates passwords with only 27 bits of entropy.

Cloud = Loss of Control

LastPass hack 2023: Millions of vaults compromised. Whoever hosts your data controls it.

2FA is Tedious

Find your phone, open the app, type the code – 50% of users disable 2FA again. Understandable.

27

AI Passwords are Insecure

Study: ChatGPT generates only 27 bits of entropy instead of 98 bits. Patterns instead of randomness – crackable in under an hour.

Proprietary Black Boxes

1Password, Ledger, Dashlane – closed source. You have to trust instead of verify.


The Same Secure Core Everywhere

A single Rust core – no reimplementation per platform. Auditable, memory-safe, blazing fast.

RUST CORE AES-256 · HKDF · CSPRNG open source · auditable 🌐 Browser Extension 💻 Desktop Tauri App CLI Terminal 📱 Mobile iOS & Android 🔐 Hardware Sentinel Vision
🌐

Browser Extension

Chrome, Firefox, Safari, Edge. Auto-fill with one click – password and TOTP simultaneously.

Available
💻

Desktop App

Windows, Linux, macOS via Tauri. 20 MB instead of 200 MB. System tray, hotkeys, auto-clear.

In Development

CLI

For admins and developers. Pipes, scripting, SSH agent – native Rust.

Available
📱

Mobile App

Android auto-fill, iOS QuickType. Native Rust core via UniFFI – no React Native.

Planned
🔐

Hardware Companion

Our vision: A physical security companion with display and FIDO2. More details under Vision.

Vision

7 Features No
Competitor Offers

Not one. Not two. Seven unique selling points that make PluriKey the first truly complete security platform.

1

CSPRNG Instead of AI Randomness

Cryptographically secure random generator directly in the Rust core. No patterns, no bias – true entropy for every password.

2

Local-First, Cloud-Optional

Your vault belongs to you – on your device. Sync only when you want: P2P, self-hosted, or completely offline.

3

P2P Git Sync Without Cloud

Synchronize your vault directly between devices – encrypted, versioned, without middlemen. Or: self-hosted, air-gapped, local.

4

2-von-4 Threshold Recovery

Distribute your master key among 4 trusted people. 2 are enough for recovery – no single point of failure.

5

KI-Agent Credential Management

Your AI needs credentials? PluriKey provides them – with time limits, mandatory justification, and complete audit trail.

6

Hash-Chain Audit Trail

Every action is logged in a tamper-proof hash chain. Compliance-ready for SOC2, ISO 27001, GDPR.

7

100% Open Source

Core, extension, server – everything open source and auditable. Check the code, verify the crypto. No trust required.

Where We're Heading

PluriKey thinks security further – beyond software. We are exploring how a physical hardware companion could take passwords, FIDO2, and entropy generation to a new level.

Concept Phase
🔐

PluriKey Sentinel

Our vision of an open-source hardware companion:
A device with display that combines FIDO2 authentication, physical entropy generation, and approval workflows – fully open source.

🔑 FIDO2 Authenticator
🎲 Entropy Sensors
👁 Approval Display

Sentinel is in early concept phase. We will keep you informed as news develops.

PluriKey vs. the Others

Honest comparison. Green checks only for actually available features.

Feature 1Password Bitwarden KeePass Ledger PluriKey
Open Source Core Partial ✓ Complete
Cloud-Free by Default Paid Complex ✓ 4 Options
FIDO2 / Passkeys
KI-Credential Management Unique *
2-von-N Threshold Recovery ✓ 2-of-4
Hash-Chain Audit Trail
Price (yearly) 36 EUR/Jahr 10 EUR/Jahr Kostenlos 79 EUR (one-time) Free *

* In development or planned. See Roadmap for current status.

Where We Stand –
and Where We're Going

Transparency matters to us. Here you can see exactly what's done, what we're working on, and what's planned.

Phase 0–2

Rust Core & Architecture

AES-256-GCM vault, HKDF key derivation, age encryption, CLI, CSPRNG – all in Rust.

Phase 3 – Current

Browser Extension

Chrome & Firefox extension with auto-fill, password generator, TOTP, 7 themes, vault browser.

Phase 4

Desktop App (Tauri)

Native desktop app for Windows, Linux, macOS. System tray, hotkeys, biometric unlock.

Phase 5 – Vision

Hardware Companion (Concept)

Exploring an open-source hardware companion for physical security and FIDO2.

Phase 6

Mobile Apps

Android & iOS with native Rust core via UniFFI. Auto-fill service, biometrics, offline vault.

Phase 7–8

Teams & AI Credentials

Multi-user vault sharing, peer approval workflows, and secure credential management for AI agents.

Phase 9+

Extensions & Integrations

Additional security features and integrations based on community feedback and demand.

Security for Every Need

Open source is free. Premium features are fairly priced.

Free
0 EUR
For beginners and privacy enthusiasts
  • 1 Vault, 25 Entries
  • Local Storage
  • Password Generator (CSPRNG)
  • Browser Extension
  • CLI Access
  • Open Source – always
Start for Free
Business
5,99 EUR / User / Monat
For teams with compliance requirements
  • Everything from Personal
  • Multi-User & Group Vaults
  • Peer-Approval Workflows
  • Hash-Chain Audit Trail
  • KI-Agent Credential Mgmt
  • LDAP/SSO Integration
Contact

* Premium features will become available as each platform is completed.

Trust Through Transparency

Every line of code is public. Check the core, audit the crypto, verify the firmware.

Rust Core

Memory-safe, auditable, blazing fast

🌐

Extension

Browser integration, fully open source

🔧

CLI & Server

Self-hosted server, CLI tools, all APIs open

📚

Protocol

Sync, crypto, audit – documented & open

Source Code on GitHub

Ready for real security?

Start for free with the browser extension – open source, local, secure. No cloud needed.