Reference

Glossary

Plain-language definitions of the terms used in the GrailVault documentation.

Term Meaning
Argon2id A password-to-key function that is deliberately slow and uses a lot of memory, so guessing passwords is expensive. GrailVault uses it to turn your master password into keys.
Authenticator app A phone app that shows a 6-digit code that changes every 30 seconds, used for two-factor authentication.
Auto-save The browser extension offering to save a login after you sign in. See Fill and save logins.
Backup code A single-use code that lets you sign in if you lose your authenticator app.
Breach check An optional check of whether a password has appeared in a known data breach. See Security check.
Ciphertext Data that has been encrypted and looks like random noise. It is all the server ever stores of your vault.
CSV A simple spreadsheet-style text file. Browsers and password managers use it to export passwords. It is not encrypted.
Device unlock Opening your vault with Windows Hello, your phone's lock, Touch ID or Face ID. See Device unlock.
Encryption key and login key Two independent keys derived from your master password. One protects your data and never leaves your browser; the other only proves who you are when signing in.
Extension The GrailVault add-on for your browser that fills and saves logins. See Install the browser extension.
HTTPS The secure version of HTTP, with a padlock in the browser. GrailVault always uses it.
Login An item with a website, a username and a password. The everyday item type.
Master password The password that protects your vault. It never leaves your browser and cannot be recovered.
PRF A feature of WebAuthn that lets a device provide a secret that never leaves it. GrailVault uses it for device unlock.
Read-only What your vault becomes after the free trial if you have no plan: you can view, copy and export everything, but not add or change items. See Plan and billing.
Recovery key A one-time key shown at sign-up that lets you reset a forgotten master password without losing data. See Recovery key.
Session Your signed-in state on one device or browser. See Active sessions.
TOTP Time-based one-time passwords: the codes an authenticator app produces.
Vault key A random key that encrypts every item in your vault. It is stored only in encrypted form.
WebAuthn The web standard behind passkeys, Windows Hello and security keys.
XChaCha20-Poly1305 The authenticated encryption method GrailVault uses to encrypt and protect your items and keys.
Zero-knowledge A design in which the service cannot learn the contents of your data. GrailVault is built this way: the server stores only ciphertext.