Vault health
The Health tab reviews your passwords, entirely on the device, and tells you which ones deserve a change.
Three local checks
- Weak: estimated entropy under 50 bits, keyboard sequences, dictionary words, common patterns.
- Reused: the same password on several items. A breach on one compromises the others.
- Old: not changed for more than a year (adjustable period).
Each finding leads to the item concerned, where the generator offers a replacement.
Known data breaches
On request only, Rempar checks your passwords against the Have I Been Pwned database using k-anonymity:
- The device computes the SHA-1 hash of the password.
- Only its first 5 characters are sent to the service.
- The service returns all hashes starting that way (several hundred).
- The full comparison is done on the device.
Neither the password, nor its full hash, nor the item's name leaves the device. The service cannot know which of the candidates you are interested in.
A password present in a breach is marked Known data breach, in red, with the number of occurrences. Change it everywhere it is used.
Since 11 October 2026 the request goes to api.rempar.org, which merges its own compromised-password database (refreshed weekly) with Have I Been Pwned server side: the device never talks to a third party. The same check appears live, as an icon, while a password is typed.
Score
The health score combines the four checks. It is not sent to the server. In Cloud mode, the other devices recompute their own from their own decrypted data.
Generator
Three modes: random password (adjustable length and character sets), pronounceable phrase, PIN code. Entropy is shown in bits. The result can be copied with the usual countdown or inserted directly into the item being edited.
A question not answered here? support@rempar.org