Local or Cloud
Rempar works in two modes. Encryption is strictly identical in both: your vault is sealed on your device, with keys derived from your master password.
Local mode
- A single encrypted file,
rempart-local-vault, on this device only. - No account, no server, no network connection, except the breach check if you run it.
- Free, with no limit on items or categories.
- Backups are your responsibility: encrypted
.rempartexport or system backup (Time Machine, etc.).
Local mode suits you if you work on a single device or if you want no data outside your home, even encrypted.
Cloud mode
- The vault is encrypted on the device, then the sealed blobs are sent to the Rempar server.
- All your devices receive the changes: Mac, iPhone, iPad, Android, Linux.
- Revision history, with conflicts kept as a "(conflict)" copy.
- Account protected by a master password (never transmitted) and Google Authenticator 2FA.
- Devices listed and revocable remotely.
Cloud is a subscription. Every account starts with a 30-day trial period. See pricing.
What the server sees in Cloud mode
| The server stores | The server never sees |
|---|---|
| Your e-mail address | Your master password |
| A hash of the authentication key | The master key, the wrap key, the vault key |
| The public Argon2id parameters (salt, memory, passes) | The content of an item |
| The sealed vault key | The name of an item |
| Opaque blobs and their revision number | Your recovery kit |
| The name and platform of your devices |
Switching modes
- Local to Cloud: Settings, Account, Create an account. The sealed vault is sent as is. Nothing is re-encrypted with a weaker key.
- Cloud to Local: Settings, Account, Switch to local. The vault stays complete on the device. You can then delete the account: all server data is erased.
When the subscription expires
Sync stops. The application shows "Pending" in the sync status and keeps working normally in local mode. Nothing is deleted. You can subscribe again at any time.
A question not answered here? support@rempar.org