The password manager, redesigned.

Bittery is end-to-end encrypted, built on a Rust crypto core, and designed like it matters — because the software holding everything you log in to should be software you love to open.

Zero-knowledge encryptionSource-availableSelf-hostable
Source-available on GitHubOne Rust crypto coreZero-knowledge: SRP-6a + AES-256-GCMSelf-hostableEvery platform

Features

Sweating the pixels.
Sweating the crypto.

Every detail is deliberate — from the hairline borders to the 96-bit IVs. The same care you can see went into everything you can't.

Sentinel — your whole security posture, live

A prioritized briefing, not a wall of warnings. Sentinel scores every vault, flags weak, reused and aging passwords, and tells you exactly what to fix first.

124 monitored
2 reused passwordsHigh priority · jumps straight to the itemsFix
1 weak passwordCrack-time estimate: under a dayFix

Travel Mode

Cross a border. Leave nothing to find. Marked vaults vanish from every device until you're through.

PPersonalSafe
WWorkSafeHidden

Autofill that can't be phished

Isolated in its own Shadow DOM and iframe, matched by exact hostname. Fills, never leaks.

Password

Filled by Bittery

github.com · matched exactly

Passkeys, ready

Passwords, passkeys, and everything after — one vault for the whole messy decade in between.

figma.comPasskey · synced to 5 devicesActive

Share a secret, not a screenshot

Expiring links, one-time views, verified recipients — with an access log you can revoke from.

bittery.com/s/x7Kf…q2One-time link

Everywhere you are — one vault, every device

One encrypted vault on web, desktop and mobile, with autofill in your browser. Every change syncs across all of them in seconds.

WebmacOSWindowsLinuxiOSAndroidExtension

All devices in sync · end-to-end encrypted, no exceptions

How it's built

We can't read your vault.
Not won't — can't.

Everything is encrypted on your device before it touches the network. Here are the receipts.

AES-256-GCM

Encrypted on-device

Every item is sealed before it leaves your machine, with ciphertext bound to its vault so it can't be swapped or replayed.

PBKDF2 · 600,000 → HKDF

Two keys, not one

Your master password plus a device-held Secret Key derive your keys. Guessing one gets an attacker nothing.

SRP-6a

Password never transmitted

Login uses a zero-knowledge proof. Your password never crosses the wire — not even hashed.

Rust → WASM & native

One audited crypto core

All cryptography lives in a single memory-safe Rust core, compiled for every platform. No JavaScript crypto.

The full source is available to read, and so is the threat model.Read the security model

Switch in minutes

Leave your old manager behind.

Switching password managers sounds painful. It takes about three steps and a few minutes.

01≈ 2 min

Import in one click

Bring everything over from 1Password, Bitwarden, LastPass, Chrome, and most other managers. Export a file, upload it, done — items are encrypted on your device before they're stored.

1password-export.1pux142 items · logins, cards, notes
Encrypting on your device…
1PasswordBitwardenLastPassChrome
02automatic

Sync everywhere, encrypted

Your vault syncs end-to-end encrypted to every device. Desktop, web, and browser extension all read the same vault — the server only ever sees ciphertext.

DesktopWebExtension
Server stores 9f3a…c14b — ciphertext only
03same day

Autofill and forget

The extension fills logins, cards, and TOTP codes right where you need them. Your old manager can come off your devices the same day.

Verification code

Filled by Bittery
OldManager.appremoved
Hosted beta coming soon

Be first in line.

Drop your email and we'll send you an invite as soon as the hosted beta opens.

We only need your email for the beta queue.

Self-hosting is available right now — no waitlist needed.

Frequently asked questions

Everything you need to know about Bittery.

Your passwords, truly yours.

Set up in two minutes. Import from 1Password, Bitwarden or LastPass. Leave anytime — your data exports with you.