←ALL DEVELOPMENT PROJECTS
PERSONAL PRODUCT
Active Development

(SYS.04) — PERSONAL PRODUCT — LOCAL-FIRST MOBILE SECURITY

Vaultify

Privacy-first, offline-first password manager with AES-GCM-256 local encryption.

YEAR: 2025–2026ROLE: Creator & Mobile Developer
Vaultify Mobile Password Manager Application Screen

(01) — System Overview

PROJECT
CONTEXT.

A privacy-first, local-first hybrid mobile password manager built with Ionic Vue, TypeScript, and Capacitor. Encrypts sensitive credentials on-device using authenticated AES-GCM-256 and PBKDF2 key derivation, supporting master-password, six-digit quick PIN, and native biometric unlock without requiring a cloud account.

The Operational Bottleneck / Problem

Cloud password managers introduce third-party breach risks, mandatory subscription models, and privacy trade-offs for users who prefer keeping sensitive credentials strictly on their personal hardware.

Engineering Solution

Created a standalone, zero-cloud mobile application that keeps encryption keys and credentials securely contained on-device.

(02) — Architecture & Pipeline

SYSTEM
ARCHITECTURE.

Ionic Vue mobile client executing SubtleCrypto Web Crypto APIs for encryption/decryption, persisting encrypted blobs via Capacitor Preferences, with native platform biometric hooks.

Data & Execution Pipeline

01. Master Password / PIN / Biometrics
→
02. PBKDF2 Key Derivation / Unwrapping
→
03. SubtleCrypto AES-GCM Engine
→
04. Encrypted Vault Blob
→
05. Capacitor Local Preferences Storage

(03) — Technical Focus

ENGINEERING
HIGHLIGHTS.

HL.01

Local-First Zero-Knowledge Architecture

Vault data is encrypted locally using 256-bit AES-GCM before writing to device storage; core credential functionality operates completely offline without remote accounts or server dependencies.

HL.02

Multi-Tier Unlock around a Single Vault Key

Engineered a unified vault key architecture that permits unlocking via master password, wrapped six-digit PIN, or native platform biometrics (fingerprint/Face ID) without storing plaintext passwords.

HL.03

Encrypted Portability & Backups

Developed portable encrypted backup export and restore functionality, requiring the master password for decryption while excluding raw biometric secrets from backup payloads.

HL.04

Lifecycle-Aware Memory Protection

Implemented automatic vault locking on app backgrounding and inactivity timeouts, purging sensitive decrypted credentials from in-memory state.

(04) — Implemented Capabilities

CORE
FEATURES.

01.

Local authenticated AES-GCM-256 credential encryption

02.

Master password derivation via PBKDF2 + SHA-256 with high iterations

03.

Six-digit quick PIN unlock with attempt-lockout protection

04.

Native platform biometric unlock (Fingerprint / Face ID)

05.

Cryptographically secure password generator with character filters

06.

Password strength analysis powered by zxcvbn-ts

07.

Encrypted JSON backup export and password-authenticated restore

08.

Category organization, favorites tagging, and instant search

09.

Configurable inactivity auto-lock and background purge

10.

Automated Android release builds via GitHub Actions

(05) — Technology Stack

STACK
ARCHITECTURE.

Mobile & UI

Ionic Vue 8Vue 3 Composition APITypeScriptVitePiniaCustom Design System

Native & Runtime

Capacitor 6Capacitor PreferencesCapgo Native BiometricAndroid Gradle

Cryptography & Security

Web Crypto API (SubtleCrypto)AES-GCM-256PBKDF2 + SHA-256zxcvbn-ts

DevOps & CI/CD

GitHub ActionsAutomated Android Release BuildsAPK / AAB Publishing

(06) — Problem Solving

TECHNICAL
CHALLENGES.

CHALLENGE 01

Balancing Convenience with True Offline Security

Designed an encrypted key-wrapping scheme that allows quick PIN and biometric convenience while ensuring the underlying 256-bit vault key remains cryptographically sealed at all times.

(07) — Reliability & Governance

SECURITY & TESTING.

Privacy & Security Model

Zero cloud databases, zero telemetry tracking, and zero plain credential transmission. Web Crypto API ensures hardware-backed cryptographic execution.