Full Security Suite. Zero Cloud.
Every capability in Lokker is engineered to execute locally on your device without transmitting telemetry or credentials to external servers.
Zero-Knowledge Password Vault
Store login credentials with custom categories, tags, notes, and password history. Features instant 1-click clipboard copy with automatic 30-second clipboard clearing and direct site links.
- AES-GCM 256-bit authenticated encryption with random IVs
- Multi-strategy password generator (passphrases, patterned, high-entropy symbols)
- Zero server authority: secrets decrypted only into ephemeral memory
- Auto-clearing clipboard buffer for sensitive data protection
GitHub
alex@example.com
ProtonMail
alex.vault@proton.me
Manifest V3 Browser Extension
Real browser autofill for Chrome, Edge, and Chromium browsers. Operates inside an isolated Shadow DOM container with strict origin verification to protect against clickjacking and DOM tampering.
- Isolated Shadow DOM prevents host page script access
- Strict origin verification against phishing attacks
- Floating repositionable fill button that never blocks form fields
- Offline synchronization directly from local browser storage
Autofill active credentials via 1-click authorization.
Integrated 2FA TOTP Authenticator
No need for a separate phone authenticator app. Lokker generates standard RFC 6238 6-digit TOTP verification codes with 30-second live circular timers and 1-click clipboard auto-copy.
- Standard RFC 6238 TOTP algorithm with HMAC-SHA1
- Live circular countdown timers with visual cadence
- Manual base32 secret input and standard otpauth:// URI parsing
- Eliminates dependency on mobile device cloud backups
AWS Root 2FA
839 204
18s
Security Health & Breach Detection
Automated local audit of password entropy, reuse across services, and dark web breach checks using k-Anonymity mathematical privacy (SHA-1 5-character prefix search).
- k-Anonymity 5-char SHA-1 prefix check (zero plaintext leak)
- Automated password reuse detection across all stored accounts
- Stale and weak credential scoring with actionable guidance
- No forced arbitrary rotation — actionable security first
0 breached • 0 reused • 0 weak credentials detected.
WebAuthn PRF Biometric Unlock
Derive symmetric encryption keys directly from your device hardware passkey (Touch ID, Windows Hello, or YubiKey) using the WebAuthn PRF extension without storing master passwords.
- Hardware-bound symmetric key derivation via FIDO2 authenticator
- Master password never stored or XORed in local storage
- Zero-friction biometric unlock with genuine cryptographic backing
- Fallbacks strictly fail-closed if hardware authenticator is removed
Touch ID / Passkey Active
Hardware key ready
Optional Cloud Sync & Team Workspaces
Need cross-device synchronization or team collaboration? Lokker offers an optional, end-to-end encrypted cloud relay powered by Fastify v5 and Neon Serverless Postgres. Zero-knowledge guarantees ensure the server only stores encrypted blobs.
- 100% Optional: Lokker never mandates cloud signup — offline mode works forever
- Zero-Knowledge Boundary: PBKDF2 keys remain strictly on client devices
- Neon Serverless Postgres: Enterprise SQL backend with instant autoscaling
- Team Workspaces (Coming Soon): Role-based access control (Admin & Member) for shared organization vaults
Local Vault (AES-GCM) ⟷ Fastify / Neon Cloud Relay ⟷ Team Workspaces (RBAC)