Your Data Doesn't Ooze

Zero-knowledge encryption that keeps your cards, accounts, credentials, and personal documents sealed tight. Share securely with real-time access control you can revoke at any moment.

Get Started Free Download Desktop App
End-to-end encrypted
Zero-knowledge architecture
Open source
No subscription required

We Never See Your Data

Everything is encrypted on your device before it leaves. Our servers only store encrypted blobs that are mathematically impossible to decrypt without your password.

🔐
Your Device
Encryption happens here.
Your password never leaves.
AES-256-GCM
Encrypted blob only
☁️
Ooze Server
Stores encrypted data.
Cannot decrypt anything.
ZERO KNOWLEDGE
Key exchange + TOTP
👤
Recipient
Decrypts on their device.
Ephemeral view only.
X25519 + HKDF

More Than a Password Manager

A complete system for managing and sharing your most sensitive data.

💳

Cards, Accounts & Credentials

Store credit cards, bank accounts, logins, personal documents, and rewards programs — all encrypted with military-grade security.

🔗

Owner-Controlled Sharing

Share a card with someone and stay in control. Every view requires a real-time authorization code. Revoke access instantly — the data is gone.

👁️

Ephemeral Viewing

Recipients see your data temporarily — it's never stored on their device. Memory is zeroed when they close the page.

🖥️

Desktop, Terminal & Web

Native macOS app, blazing-fast terminal interface, and secure web viewer. Your vault syncs across all of them, encrypted end-to-end.

🛡️

Two-Layer Protection

Master password protects your vault. Optional PIN or Touch ID adds a second layer for sensitive fields. Defense in depth.

🏢

Enterprise Ready

Domain-based security policies, Duo Push integration, mandatory 2FA, and SSO support. Built for teams that handle sensitive data.

Built Different

Most vault products store a copy of your secrets and call it sharing. We believe you should never lose control of your data.

Ooze Encrypt Traditional Vaults
End-to-end encryption
Zero-knowledge architecture
Real-time share access control
Ephemeral viewing (no persistent copy)
TOTP-gated share access
Instant share revocation
Works without an account (local vault)
No subscription for basic use
Open sourcePartial

How Sharing Works

1

You share a card

Select a card and enter the recipient's email. Ooze encrypts it using a unique key derived from a cryptographic key exchange — only the recipient can decrypt it.

2

They get a notification

The recipient receives an email inviting them to view the shared card. If they don't have an account, they can sign up and view it instantly in their browser.

3

You authorize each view

Every time the recipient wants to see the card, they need a 6-digit code from you. This code changes every 30 seconds. You're always in the loop.

4

Revoke anytime

Press one button and the share is gone. The encrypted data is deleted from the server. The recipient gets nothing — not even an error message, just silence.

Ooze Encrypt uses the same proven encryption standards trusted by leading security products like Bitwarden — including AES-256-GCM for data encryption, Argon2id for key derivation, and X25519 Diffie-Hellman for secure key exchange. Our architecture is open source and auditable. We don't invent our own cryptography — we use the industry standards that security researchers have vetted for decades.

AES-256-GCM Argon2id X25519 HKDF-SHA256 TOTP RFC 6238 WebAuthn

Stop the Ooze

Free to use. No credit card required. Your vault, your rules.

Create Your Vault View on GitHub