Password manager
SafePass
A password manager that guards your vault on the device too, not just in the cloud.
SafePass keeps passwords in an encrypted vault and adds safeguards a phone needs: copied passwords are cleared, a shake logs you out, a shutdown ends the session, and public Wi-Fi gets a warning.
- Role
- Mobile app
- Team
- Two developers
- Year
- 2024
- Platform
- Android
- Backend
- Go API
- Status
- Finished
What it does
-
Encrypted vault
Save, browse and open passwords from a single vault after signing in.
-
Clipboard auto-clear
A copied password is wiped from the clipboard after a set time, so it can’t be pasted by accident later.
-
Shake to lock
The motion sensor watches for sudden movement, like a grab or a shake, and logs you out at once.
-
Session ends on shutdown
When the device powers off, the session is terminated before anyone can reopen it.
-
Public Wi-Fi warning
The app checks the current network and warns you when it’s open or unsecured.
-
Stays signed in safely
Tokens and user data are kept in a local database, the secret key in private app storage.
How it’s built
- Master password
- PBKDF2
- HKDF
- Protected key
- ChaCha20-Poly1305
-
01
Cryptography lives in a native Expo module written in Kotlin. PBKDF2-HMAC-SHA256 derives a master key from the master password and email, and HKDF stretches it into separate encryption and MAC keys.
-
02
A random symmetric key is encrypted with AES-256-CBC and signed with HMAC-SHA256 to form the protected key; vault entries are sealed with ChaCha20-Poly1305.
-
03
Key derivation runs on background coroutines, so slow, deliberately expensive hashing never blocks the UI.
-
04
Device safeguards hook into the platform: a Broadcast Receiver for shutdown, the motion sensor for shakes, a background clipboard timer and a Wi-Fi security check.
Stack
- React Native
- Expo
- Expo Modules
- Kotlin
- React Native Paper
- Jotai
- React Navigation
- SQLite
- Go