Zero Knowledge architecture

What we don't know,
can't be stolen

Zero Knowledge isn't technical jargon — it's a simple promise: Cleverpass is built so that not even we can see your passwords. If we don't know them, no one can take them from us.

No one can see your data
No servers hold your data
Immune to breaches
Encrypted on your device

What is Zero Knowledge? In plain words

No jargon. Here's the explanation you'd give to someone who doesn't know anything about technology.

🔒

Imagine a safe only you know

Think of a bank. When you deposit money, the bank stores it in its safe. They have the key. If someone robs the bank, they steal your money. If an employee is corrupt, they can access your money.

Zero Knowledge is the opposite: imagine you bring your own house padlock — with your own unique key — and install it inside the bank's safe. The bank only stores the metal box. It never had your key. It cannot open it. It does not know what's inside.

💡 This is how Cleverpass works: we keep an encrypted box on your device that only you can open. We don't have your key (your master password). We cannot see what's inside. And if someone steals the box, they only get a meaningless jumble of data.
📮

Another way to see it: the sealed envelope

When you send a letter in a sealed envelope, the mail carrier transports it. They don't know what it says inside. If the carrier loses the envelope or someone steals it, the message remains unreadable to anyone who is not the recipient.

Cleverpass is the mail carrier. It moves your data (encrypted) between your device and your Google Drive. It never opens the envelope. It never reads the message.

💡 The message can only be read by you, because only you have the key to open it: your master password, which never leaves your device.

How it works step by step

This is the journey of your password from the moment you type it until it is stored. No intermediaries can read it.

👤
You type Your master password
Only on your
device
📱
Your device Generates the encryption key
Encrypted data
🔐
AES-256 encryption Unreadable vault
Only the encrypted
file
☁️
Your Google Drive Your property
Cleverpass
does not pass
🏢
Cleverpass No access
1
Your master password never leaves

When you enter your master password, it is used on your device to generate a cryptographic key. That key is never sent to any server. It only exists on your device while you enter it and is erased immediately after processing.

2
Encryption happens on your device

Your data is fully encrypted before leaving your phone or computer. What travels over the internet or is stored in the cloud is an encrypted file that is meaningless without your key.

3
Only you can decrypt

To read your passwords you must have the key, and the key is generated by your master password. Without it, the encrypted file is random garbage to anyone who intercepts it.

Cleverpass does not have servers with your data

This is not an accident. It is a deliberate architectural choice that makes the system mathematically more secure.

Why not having servers is more secure?

Many password managers store your vaults on their servers. That means there is a juicy target for hackers. We remove that target completely.

Your data lives on your device or your Google Drive

The permanent storage of your vault is on hardware you control. Cleverpass never has a copy of your decrypted or permanently encrypted data.

Works without internet

Because the source of truth is local, you can access all your passwords offline. If our servers went down or we shut down tomorrow, your data would still be yours and accessible.

Your Google Drive is your property

Synchronization uses your own Google Drive account. Cleverpass does not have a shared storage account where thousands of users' data lives. Each user has their own isolated, independent space.

No target for hackers

To steal password from Cleverpass users, an attacker would need to compromise each individual device of each user. There is no central database to offer as a reward.

Zero Knowledge vs. traditional managers

Not all password managers are the same. Here is the real difference.

Feature
✅ Cleverpass (ZK)
⚠️ Traditional manager
Data stored on proprietary servers
 Does not store
 Stores it
Encryption on the user's device
 Always
 Sometimes
Provider can see your passwords
 Impossible
 Potentially
Impact of a provider breach
 None
 High risk
Full offline access
 Yes, always
 Limited
Your data survives if the service closes
 Yes
 Depends
One user's data isolates the rest
 Completely
 Shared database

What if...? The most common attacks

This is how Zero Knowledge architecture responds to the most frequent attack scenarios.

Cleverpass servers are hacked

An attacker gains access to Cleverpass internal infrastructure.

They get no user data. There are no vaults or user accounts in our infrastructure.
A Cleverpass employee acts maliciously

Someone with internal access tries to spy on users' passwords or sell them...

Impossible. Employees do not have access to vault data because that data does not exist in our systems. There is nothing to spy on or sell.
Someone accesses your Google Drive

Because of a security flaw or phishing, an attacker gains access to your Google Drive account and downloads your vault...

They obtain a fully encrypted file. Without your master password it is mathematically impossible to decrypt the data. A useless file.
They intercept the connection between your app and Google Drive

A man-in-the-middle attack intercepts traffic while you sync your data...

The data already travels encrypted from the device. Intercepting the traffic would only give access to the same unreadable file that is on Google Drive.

Myths about Zero Knowledge

We clarify the most frequent doubts that arise when this architecture is explained.

MYTH

"If you don't have my data, how can you recover my account if I forget the password?"

TRUTH

We can't recover your master password — and that is precisely the guarantee that no one else can either. It's like the combination to a safe: only the owner knows it. That's why it is so important to choose a memorable master password and save the recovery code we offer when you set up the app.

MYTH

"Zero Knowledge means the app can't do anything useful with my data"

TRUTH

Don't confuse "Cleverpass can't see your data" with "the app can't process it." The app decrypts your data on your own device and can do everything required: autofill, search, organize, sync. The difference is that this processing happens locally, not on our servers.

MYTH

"This only matters if I am a target of professional hackers"

TRUTH

Massive password manager breaches affect ordinary users, not specific targets. LastPass, for example, was hacked in 2022 and millions of ordinary users' vaults were exposed. With Zero Knowledge architecture that simply cannot happen.

MYTH

"If you use Google Drive, Google can see my passwords"

TRUTH

Google only sees an encrypted, unreadable file in your Drive, just like it sees encrypted files from any other app. Without the decryption key (your master password, which Google never has), the file is completely incomprehensible. Google doesn't even know it's a password manager.

The most secure architecture. Free forever.

Zero Knowledge is not a premium feature. It is the foundation of how Cleverpass works from day one, for all users.

Download Cleverpass free