Reference
Glossary
Plain-language definitions of the terms used in the GrailVault documentation.
| Term | Meaning |
|---|---|
| Argon2id | A password-to-key function that is deliberately slow and uses a lot of memory, so guessing passwords is expensive. GrailVault uses it to turn your master password into keys. |
| Authenticator app | A phone app that shows a 6-digit code that changes every 30 seconds, used for two-factor authentication. |
| Auto-save | The browser extension offering to save a login after you sign in. See Fill and save logins. |
| Backup code | A single-use code that lets you sign in if you lose your authenticator app. |
| Breach check | An optional check of whether a password has appeared in a known data breach. See Security check. |
| Ciphertext | Data that has been encrypted and looks like random noise. It is all the server ever stores of your vault. |
| CSV | A simple spreadsheet-style text file. Browsers and password managers use it to export passwords. It is not encrypted. |
| Device unlock | Opening your vault with Windows Hello, your phone's lock, Touch ID or Face ID. See Device unlock. |
| Encryption key and login key | Two independent keys derived from your master password. One protects your data and never leaves your browser; the other only proves who you are when signing in. |
| Extension | The GrailVault add-on for your browser that fills and saves logins. See Install the browser extension. |
| HTTPS | The secure version of HTTP, with a padlock in the browser. GrailVault always uses it. |
| Login | An item with a website, a username and a password. The everyday item type. |
| Master password | The password that protects your vault. It never leaves your browser and cannot be recovered. |
| PRF | A feature of WebAuthn that lets a device provide a secret that never leaves it. GrailVault uses it for device unlock. |
| Read-only | What your vault becomes after the free trial if you have no plan: you can view, copy and export everything, but not add or change items. See Plan and billing. |
| Recovery key | A one-time key shown at sign-up that lets you reset a forgotten master password without losing data. See Recovery key. |
| Session | Your signed-in state on one device or browser. See Active sessions. |
| TOTP | Time-based one-time passwords: the codes an authenticator app produces. |
| Vault key | A random key that encrypts every item in your vault. It is stored only in encrypted form. |
| WebAuthn | The web standard behind passkeys, Windows Hello and security keys. |
| XChaCha20-Poly1305 | The authenticated encryption method GrailVault uses to encrypt and protect your items and keys. |
| Zero-knowledge | A design in which the service cannot learn the contents of your data. GrailVault is built this way: the server stores only ciphertext. |