Twofold is built so that nobody but the people you pair with can read your vault, including us. There's no Twofold server, so there's nothing to break into. Here is exactly how it works.
The keys
Master password ──Argon2id──▶ Password key
│ unlocks
▼
Your private key (X25519)
│ opens
▼
Vault key, sealed separately for each member
│ unlocks
▼
Item keys ──▶ items and attached documents
- Master password: turned into a key with Argon2id, a deliberately slow, memory-hard function that makes guessing passwords very expensive. Your password never leaves your phone.
- Your identity: each phone makes an X25519 key pair. The private key is stored only encrypted.
- The vault key: a random 256-bit key, sealed separately to each family member's public key. Adding someone means sealing one more copy for them.
- Items: each item has its own random key and is encrypted with XChaCha20-Poly1305. Any tampering is detected and rejected.
- Documents: scans and PDFs are encrypted in chunks with libsodium's secretstream.
All of this uses libsodium, a widely used and audited cryptography library. Twofold doesn't invent its own encryption.
Pairing in person
When you add a family member, you scan each other's QR code. The code holds a fingerprint of each phone's public key, so nobody can secretly slip in a key of their own. The vault key is then sealed to the new member's verified key.
Syncing between phones
Paired phones on the same Wi-Fi network find each other and exchange changes over an encrypted, authenticated connection using the keys you swapped when pairing. Other devices on the network can't read or fake the traffic. Only encrypted items are ever sent.
Backups
Each phone can keep one encrypted backup in its owner's own Google Drive, in a private, hidden app folder, and you can also save a backup file yourself. The backup is encrypted before it leaves the phone, so Google only ever sees an unreadable file, and opening it needs your master password or recovery key. Twofold only asks for access to that private app folder, never to the rest of your Drive.
On your phone
- Unlock with fingerprint or face, backed by the phone's secure hardware (Android Keystore, iOS Keychain).
- Auto-lock when you leave the app.
- Screenshots and the app-switcher preview are blocked.
- Copied passwords are cleared from the clipboard after 30 seconds.
- Notifications never show private details.
The honest trade-offs
- We can't recover your vault. Keep your printed recovery kit safe. If you lose your master password, recovery kit and every paired phone, the data can't be recovered by anyone.
- A phone that is unlocked and in someone else's hands is outside what any app can protect. Keep your phone's screen lock on.
Found a security issue?
Please tell us privately through the support page before sharing it publicly. We'll reply quickly.