SpokPass
On-device encryption · Argon2id + AES-256-GCM

Your passwords are encrypted before they ever leave you.

This isn't marketing language, it's how the product is built: the key is derived from your master password, on your own computer, and never leaves it. SpokPass servers receive blocks they cannot open — not us, and not anyone who steals our database.

Export anytime, in an open format · No surprise auto-renewal · Your data stays yours

The proof

What you see, and what the server sees

You don't have to take our word for it. Open your browser console, the Network tab, and save a password: what goes to the server looks like the panel on the right.

In your browser
TitleBanca Transilvania
Usernamejohn.smith
PasswordL7#kQ2vw!mZ4pR9t
Notespare card in the drawer
In our database

Plus a few housekeeping fields: when it was last changed and which folder it sits in. That's all. The title, the address, the username, the password and the notes are all inside the block.

The consequence, said plainly: if you forget your master password and lose the recovery kit you got at sign-up, the data in your vault is gone for good. There is no “forgot my password, send me a link” — we have nothing to open your vault with. That is the price of nobody else being able to open it either.
The mechanism

What happens when you save a password

01

The key is born on your device

Your master password produces an encryption key, on your own computer. The process is deliberately slow and memory-hungry (Argon2id, 64 MiB), so it can't be attempted millions of times on a graphics card.

02

The data is sealed locally

Everything that means anything goes into a single AES-256-GCM block. Change one bit of it — even with access to the database — and the block refuses to open at all.

03

The server receives noise

Search happens in your browser, after decryption. A search index on the server would mean leaking exactly what we promised not to see, so there isn't one.

For companies

For companies, not just for one person

Users with roles and paid seats, an access log, revoking access when someone leaves. With one limit we state up front: not even an administrator can read someone's vault. When someone leaves, you take away their access, and work passwords get changed at the source.

Clear roles

Owner, administrator, member. Three of them, not a matrix of twenty checkboxes nobody understands six months later.

Seats, not forgotten accounts

A suspended person frees up the seat. You don't pay for years for accounts nobody remembers.

Access log

Who signed in, when, from where. Never what they opened — that would rebuild, over time, the map of their digital life.

Your data leaves, it isn't held hostage

Open-format export, any time, including after your subscription expires.

Pricing

What it costs, with no asterisk

A subscription, not a one-off payment. A vault has to be synced and guarded for as long as you use it, and a payment made in 2026 doesn't keep servers running in 2032 — anyone promising otherwise either shuts down or changes the terms along the way.

New vaults open in a few days, together with card payments.

Personal

For one person and all their devices.

20RON / month

Or 199 RON a year — two months free.

  • Passwords, cards and notes, no limit
  • Sync across every device
  • Password generator and breach checking
  • Recovery kit
  • Export any time, in an open format
Most popular

Family

Up to 6 separate vaults, plus one shared folder.

30RON / month

Or 299 RON a year — two months free.

  • Everything in Personal, for each member
  • Shared folder (Wi-Fi, subscriptions, documents)
  • Everyone has their own vault, which the others can't see
  • Emergency access for one chosen person

Team

For companies. Priced per user, minimum 3.

16RON / month / user

Or 160 RON a year per user — two months free. Minimum 3 users.

  • Folders per department, with permissions
  • Access log for every account
  • Revoking access when an employee leaves
  • Password policies enforced company-wide
  • Company invoicing, through SpokInvoice

No auto-renewal you find out about from your bank statement. Export stays open even after you leave — the data is yours, not ours.

Before trust

The questions people ask before trusting anyone

How do I know you don't read my passwords?

Not because we say so. Open your browser console, the Network tab, and save a password: you'll see a block starting with “sp1.” and nothing readable. On top of that, the cryptography lives in a single place in the code, and an automated check stops the release if anyone slips encryption elsewhere or writes a key into browser storage.

What happens if SpokPass shuts down tomorrow?

You export your vault any time, in an open format. Your data isn't a hostage — a password manager you can't leave is a trap, not a product.

If my subscription expires, do I lose my passwords?

No. The vault stays readable and exportable. Only new saves stop. The passwords are yours; the subscription pays for the service, not for the right to see your own data.

Can my company's administrator see my passwords?

No, and it isn't a setting they could change. Every vault is encrypted with its owner's key. An administrator can revoke someone's access and see when they signed in — never what they keep inside.

Who's behind this?

The same team that builds SpokAdmin (property-association management) and SpokInvoice (invoicing and Romanian e-Invoicing). Products running on real money, for real customers, for years.

Your vault. The key stays with you.

We're not asking you to trust us on our word. We show you what leaves your device, we hand you the key on the way out, and we tell you plainly what happens if you lose it.