iconHolder Cleverpass is the free password manager application
Built secure from the ground up

Your security is our
top priority


Cleverpass is designed so that no one — not us, not Google, not any attacker — can ever access your passwords. Here's how.


Security principles

Three non-negotiable pillars that define how Cleverpass handles your data.

Zero Knowledge

We never know your master password. It's never sent to any server. Only you can decrypt your vault.

No Proprietary Servers

We don't store your data. Your encrypted vault lives exclusively in your own Google Drive account.

No Proprietary Servers

Local Encryption

Encryption and decryption happen entirely on your device. Data is encrypted before it ever leaves your phone.

How we encrypt your data

A multi-layer encryption process that keeps your vault locked — even from us.

01

AES-256 Encryption

Your vault is encrypted using AES-256, the same standard used by governments and banks worldwide. It's effectively unbreakable with current technology.

02

PBKDF2 Key Derivation

Your master password is never stored directly. It's processed through PBKDF2 with a high iteration count and a unique salt, turning it into a strong cryptographic key.

03

End-to-end encryption

The encryption key is derived on your device. Only the already-encrypted blob is sent to Google Drive — Google sees gibberish, not your passwords.

04

Secure random IV per entry

Every password entry uses a unique initialization vector (IV), ensuring that identical passwords produce different ciphertexts. No patterns, no shortcuts for attackers.

Google Drive as storage

Unlike most password managers that store your data on their own servers, Cleverpass uses your personal device or optionally your Google Drive. This means:

  • Only you control who can access your Drive
  • We cannot be hacked to expose your vault
  • Your data persists even if Cleverpass shuts down
  • You can inspect, export or delete your vault anytime

Biometric authentication

On supported devices, you can unlock your vault using Face ID or fingerprint. Your biometric data never leaves your device — it's handled entirely by the OS secure enclave.

  • Fingerprint & Face ID supported
  • Biometrics never sent to any server
  • Processed by hardware secure enclave
  • Falls back to master password if needed

What we protect you from

A clear picture of the threats Cleverpass is designed to defeat.

Server breaches
No proprietary servers — nothing to breach.
Man-in-the-middle attacks
Data is encrypted before transit.
Google Drive access by Google
Google only sees encrypted ciphertext.
Cleverpass employees
Zero-knowledge — we never see your data.
Device theft
Biometric + master password required to unlock.
Weak master password
Choosing a strong master password is still your responsibility.