ZZPass is built in Norway, paid for by the people who use it, and designed so that trusting the company behind it is not part of the deal.
Most password managers ask you for a great deal of faith. Faith that the company stores your vault properly, that its employees cannot look inside, that it will not be acquired by somebody with different priorities, and that its next funding round will not require finding new ways to make money from you.
Those are reasonable things to worry about, and no promise on a marketing page can settle them. So ZZPass is built the other way around: the architecture removes the need to trust us at all. Your vault is encrypted on your device with a key derived from your primary password and your Secret Key. We hold neither. There is no copy of your data we could read, hand over, or lose.
That constraint is the whole product. It is also why recovery works the way it does: we cannot reset your primary password, so the routes back in are yours to prepare. Read how the encryption works →
I'm Jonny Rein Eriksen, and ZZPass is made in Norway. I spent 22 years at Opera Software building the web browser, mostly on the browser engine, where cryptography and security are the day job. LinkedIn →
ZZPass came out of that work, and out of two articles I wrote about BankID, the identity system four million Norwegians use to reach their bank and the public sector. I found a man-in-the-middle weakness that allowed an attacker to capture a user's national ID number, one-time code, and password, and in one case to take over a bank account outright. I reported it privately for a year before writing about it publicly in March 2019.
The following year I built Kodebrikkesjekken, a Chrome and Firefox extension that verifies a BankID dialog is genuine before you type anything into it. Vipps, which owns BankID, took a look and responded positively. In August 2020 I wrote a second piece comparing the Norwegian design with the Swedish one, which had already solved several of the same problems.
That second article was used in court to show that the weaknesses were in the banks' systems rather than in the customers' behaviour. In September 2022 the Norwegian Supreme Court ruled that a woman in her seventies who had been talked out of 140,000 kroner by scammers posing as her bank could not be made to carry the loss herself. A queue of similar cases had been waiting on the outcome.
That episode is the reason ZZPass is built the way it is. A system that asks you to trust its operator will eventually disappoint somebody, and the only durable fix is to design so that trust is not required in the first place.
ZZPass has no VC funding, no investors to answer to, and no incentive to do anything with your data but keep it safe. It is a small operation, which has consequences worth being honest about. There is no 24-hour support desk, and features arrive when they are properly done rather than on a quarterly roadmap. In exchange, there is nobody upstream asking for growth at the expense of the thing you actually bought.
The server components are public, so the claims on this site can be inspected rather than believed. The apps use Apple CryptoKit throughout, with no custom cryptography and no third-party dependencies.
ZZPass is free to use with unlimited passwords, notes, and devices. Premium costs $2.99 a month or $29.99 a year and adds Emergency Access, unlimited shared groups and attachments, and an Emergency Kit that includes your passwords and notes.
That is the entire business. There is no advertising, no free tier subsidised by anything other than the people who upgrade, and no data to sell even in principle: a vault we cannot decrypt is worth nothing to anyone but its owner. See what is in each plan →
Not aspirations. Most of these are consequences of how the app is built, which makes them harder to quietly reverse later.
support@zzpass.com, or Settings → Help & Feedback in the app. Start with the support guides.
security@zzpass.com. Please do not open a public GitHub issue for a vulnerability. Disclosure policy.
What is collected, and what is not. Privacy policy.