“Encrypted on this device” means the readable vault never sits in plain localStorage. A PIN-derived key unlocks ciphertext in the browser.
Cloud sync, when enabled, moves the encrypted blob — not your unlocked password list — so a sync target without your PIN stays opaque.
Export a backup before you change devices. Import restores the encrypted package; you unlock with the same PIN you used when you exported.
If you forget the PIN, there is no backdoor. That is the tradeoff of a vault that cannot be reset by a support inbox.
Google convenience mode is a different contract: we store a vault key and release it only to your authenticated Google session on this site. Say which mode you use before calling the product zero-knowledge. Privacy and Security use that wording on purpose.
Premium encrypted sync is optional ciphertext for another device, not an unlocked password folder in our dashboard. Turn it off if you only want this browser.
This is not a SOC 2, ISO, or insurance page. Those claims are not published here. If that changes, link a real report — not a placeholder badge.
Questions people ask
- Can LoginScout reset a forgotten PIN?
- No. There is no PIN-reset email. Export a backup while you still remember the PIN.
- Is Google sign-in zero-knowledge?
- No. Google convenience mode stores a vault key for that Google session. Use a PIN vault if you need the stricter model. Security and Privacy have the exact wording.
- Do you publish SOC 2 or ISO badges?
- Not on this site. Do not invent certifications. If an audit report is published later, the security page should link the real document.
Ready to try it?
Create a free vault and keep logins, mail, and MFA together.
Related: Security · Privacy · How it works

