VaultPass · Information
About VaultPass
A project to explain password security without jargon, with tools that work without asking you for anything.
Where this comes from
Almost all information about passwords is written for people who already know security, or it is so shallow that it changes nobody's behaviour. In between there is a gap: the people who want to get it right and cannot find anyone explaining it in ordinary terms.
VaultPass tries to fill that gap with two things: tools you can use in thirty seconds, and long pieces explaining why, for when you want to actually understand it.
Who maintains it
VaultPass is an independent project by Marcos Cebrino, a web developer. There is no security company or editorial team behind it: it is a personal project, and I would rather say so than pretend to a structure that does not exist.
That has a consequence worth keeping in mind as you read: this is explanatory writing, not consultancy. The content draws on the public recommendations of recognised bodies in the field, and where there is genuine debate or uncertainty it says so rather than faking a certainty that is not there.
If you find a mistake, write tovaultpass.info@gmail.com. It gets corrected and the article's review date is updated.
How the articles are written
- They start from a real question, not from a keyword list.
- They explain the mechanism, not just the recommendation. Knowing why a rule exists is what makes it survive the day it becomes inconvenient.
- They say what no longer applies. A good share of the security advice in circulation went out of date years ago, and repeating it does harm.
- They carry dates. Every article shows its publication date and, if revised, the review date.
- They admit their limits. No tool here guarantees anything absolute, and the text says so where it should.
How the tools are built
They all run inside your browser. That is not a marketing stance: there simply is no server of ours to send anything to. The site is a set of static files.
The single exception, explained in detail in the privacy policy, is the breach checker, which queries an external database by sending five characters of a hash — never the password — using a technique called k-anonymity.
The typefaces are hosted here too, rather than loaded from an external service. It would be incoherent to promise that no data is shared with third parties and then ask another server for a font on every visit.
How it is funded
By Google AdSense advertising. There is no paid tier, no subscription, no data selling and no sponsored articles dressed up as editorial content.
Ads are marked as such and are independent of what gets written: a company appearing in an ad is not a recommendation. If there were ever sponsored content, it would be stated clearly on the page itself.
The four principles
- Process locally wherever possible, and say clearly when it is not.
- Never promise absolute security. It does not exist, and anyone promising it is selling something.
- Teach what works: unique keys, length and two-factor authentication. In that order.
- Ask for nothing. No accounts, no sign-up, no email in exchange for a PDF.
If this is your first visit, the best place to start is thesecurity guide. If you would rather start with something practical, the strength checker takes ten seconds to tell you how the password you use right now is doing.