Security

LoginScout security: on-device encryption, PIN unlock, and what we cannot read

This page restates what Privacy, Help, and the encryption guide already say. We do not list SOC 2, ISO 27001, pentest badges, or insurance — those are not published here.

What we can honestly say

Payments

Billing goes through Stripe. We do not store full card numbers. That is in the Privacy Policy.

Temp mail and burners

Disposable inboxes store messages sent to addresses we issue. Burner numbers are purchased through 5sim; we keep order identifiers to show SMS and enforce quota.

What this is not

Not a guarantee against phishing, malware, or a stolen unlocked session. Lock the vault. Do not paste cookies or share logins you do not own.

Open questions

Independent audit reports are not published on this site. If that changes, this page should link the real report — not a placeholder badge.

How the vault is protected

  1. Step 1

    Vault items encrypt in the browser

    Logins, notes, MFA secrets, and other vault items are encrypted before they are stored. We cannot read a PIN-protected vault.

  2. Step 2

    Your PIN stays in the browser

    For username and PIN vaults, the PIN never leaves the browser. There is no PIN-reset email.

  3. Step 3

    Cloud sync is optional ciphertext

    When Premium sync is on, the encrypted blob can be stored for that account. Unlocked contents are not uploaded as a readable list.

  4. Step 4

    Google convenience mode is not zero-knowledge

    We store a random vault key and release it only to your authenticated Google session on this site. Use a PIN vault if you need the stricter model.

Related reading

The blog post on local encryption is the longer explanation of PIN-derived keys and backups. Privacy is the legal version. Terms covers Premium and third-party providers.

Questions people ask

Is LoginScout zero-knowledge?
PIN-protected vaults are encrypted in the browser and we cannot read them. Google convenience mode stores a vault key for that Google session, so it is not zero-knowledge. Say which mode you use before calling the product “zero-knowledge.”
Do you have a bug bounty?
No public bounty program is listed on this site. Email [email protected] for security issues. Do not file a fake CVE page here.

Keep the identity with the login.

Create a free vault, then add temp mail and burner numbers when the library grows.