Security

How Twofold keeps your vault safe

Twofold is built so that nobody but the people you pair with can read your vault, including us. There's no Twofold server, so there's nothing to break into. Here is exactly how it works.

The keys

Master password ──Argon2id──▶ Password key
                                  │ unlocks
                                  ▼
                  Your private key (X25519)
                                  │ opens
                                  ▼
       Vault key, sealed separately for each member
                                  │ unlocks
                                  ▼
          Item keys ──▶ items and attached documents

All of this uses libsodium, a widely used and audited cryptography library. Twofold doesn't invent its own encryption.

Pairing in person

When you add a family member, you scan each other's QR code. The code holds a fingerprint of each phone's public key, so nobody can secretly slip in a key of their own. The vault key is then sealed to the new member's verified key.

Syncing between phones

Paired phones on the same Wi-Fi network find each other and exchange changes over an encrypted, authenticated connection using the keys you swapped when pairing. Other devices on the network can't read or fake the traffic. Only encrypted items are ever sent.

Backups

Each phone can keep one encrypted backup in its owner's own Google Drive, in a private, hidden app folder, and you can also save a backup file yourself. The backup is encrypted before it leaves the phone, so Google only ever sees an unreadable file, and opening it needs your master password or recovery key. Twofold only asks for access to that private app folder, never to the rest of your Drive.

On your phone

The honest trade-offs

Found a security issue?

Please tell us privately through the support page before sharing it publicly. We'll reply quickly.