About LORIIQ
We are building a password manager for people who want proof, not promises.
Our mission
Password managers should protect people — not become the next headline breach. LORIIQ exists to restore trust through verifiable security: client-side encryption, encrypted metadata, transparent architecture, and honest communication about what we can and cannot protect.
The category has a trust problem that goes beyond any single incident. In the past year, several major password managers raised prices or reduced what their free tiers included — and users are right to ask whether vendors still earn the benefit of the doubt. LORIIQ is built for that skepticism: proof you can inspect, limits we state plainly, and no claim we have not earned yet.
Why infrastructure quarantine
LORIIQ stands for Local Ownership Rooted In Infrastructure Quarantine. The mechanism is simple: plaintext exists only on your device. Ciphertext is the only thing that ever reaches our infrastructure. We call that boundary infrastructure quarantine — our term for a stricter, more literal version of zero-knowledge architecture.
Our differentiation is not the interface or the feature checklist. Encrypted vault, password generator, sync, CLI, and browser extension follow patterns this category settled on long ago — and that is intentional, not a compromise. What we are building differently is the trust model: security you can verify rather than marketing you are asked to accept on faith.
That shows up in concrete design choices, not slogans:
- Encrypted metadata — item names, URLs, usernames, and tags are ciphertext on our servers, not just password fields.
- Per-item encryption keys — unique keys per vault item, with RSA-4096 wrapping when credentials are shared.
- Forward secrecy on sync — ephemeral X25519 key exchange for each sync session, so a past session compromise does not decrypt future traffic.
- Stated limits — our Security page says what we cannot do (reset a lost master password, recover your vault, read your secrets on your behalf). Most products in this space lead with confidence and breadth; we lead with architecture and honesty.
Incentives aligned with trust
The Individual plan is free forever — not a stripped trial, not a time-boxed teaser tier. Revenue comes from Team and Enterprise plans only. We do not need to monetize individual users' trust to survive as a business, and we structured pricing that way on purpose: your personal vault should not be the product we upsell you out of.
Who we build for
Developers who need a CLI they can script against. Security professionals who read architecture docs before they read release notes. Privacy-conscious individuals who want auditable design, not black-box assurances. Teams and enterprises that need shared credentials without handing a vendor unverifiable trust — or the keys to the kingdom.
If you evaluate tools by what they refuse to claim, you are the audience we had in mind.
Where we are today
LORIIQ is in early development. The product you see on this site is our vision and a marketing preview — not a production-ready vault. We will not ask you to store real credentials until independent security review is complete.
Compliance and independent review
SOC 2 Type II and HIPAA compliance work with Vanta is paid and actively in progress — not certified yet. An independent security audit is planned and has not been completed. We will not claim certifications or audit outcomes we have not earned. For the full security model and current status, see our Security page.
Built by VitaTech
LORIIQ is a VitaTech initiative focused on credential security done right — minimal hype, maximum rigor.