Security

Security by design.Local by default.

Raktera protects vault data with authenticated encryption and derives encryption keys locally from your Master Password. Pro licensing is cryptographically separate from vault security and does not require recurring online verification.

AES-256-GCMArgon2idEd25519 licensingLocal verification
01
Vault encryptionAES-256-GCM
02
Key derivationArgon2id
03
Random materialOperating-system randomness
04
Pro license signaturesEd25519

Core security model

Clear responsibilities. Separate security layers.

01

Encrypted vault

Vault contents are encrypted using AES-256-GCM, providing authenticated encryption for stored Raktera data.

02

Password-derived key

Raktera derives the 256-bit vault encryption key locally with Argon2id using vault-specific parameters and salt.

03

Optional keyfile

A vault can require an additional 32-byte keyfile that becomes part of the Argon2id key-derivation material.

04

Independent licensing

Pro licensing controls product capabilities only. License data does not participate in vault encryption or Master Password validation.

Vault cryptography

From Master Password to encrypted vault.

Raktera performs the key-derivation and encryption process locally. The Master Password is not used directly as an AES key.

01

Master Password

The Master Password provides the primary secret input for key derivation.

02

Optional 32-byte keyfile

If enabled for the vault, the selected keyfile is incorporated into the derivation material.

03

Argon2id

Current vaults use a 16-byte random salt, 64 MiB memory, 3 iterations, 4 lanes, and produce a 256-bit key.

04

AES-256-GCM

Vault data is encrypted with a 256-bit key. The vault header is authenticated as additional associated data.

05

Encrypted .rkt vault

The resulting encrypted vault is stored as the Raktera vault file.

Current vault parameters

Current cryptographic parameters.

EncryptionAES-256-GCM

Authenticated encryption for vault contents.

Key derivationArgon2id

Argon2 version 1.3 with a 256-bit derived key.

KDF memory64 MiB

65,536 KiB for newly created current-version vaults.

KDF iterations3

Current default for newly created vaults.

Salt128 bits

16 random bytes for newly created vaults.

AES-GCM nonce96 bits

A new 12-byte nonce is generated when the vault is saved.

Optional keyfile

A second secret can participate in key derivation.

When a vault is configured to require a keyfile, Raktera requires the selected file to contain exactly 32 bytes. Its contents are combined with the Master Password material before Argon2id derives the vault key.

Required size32 bytes
Used byArgon2id
Required when enabledYes
Stored inside vault dataNo

Offline Pro licensing

License verification is separate from vault security.

Raktera Pro uses cryptographically signed .rkl license files. Runtime verification uses trusted Ed25519 public keys and happens locally without recurring server activation.

View Pro pricing →
01

Ed25519 signatures

License payloads must pass signature verification before their contents are accepted as trusted license information.

02

Public keys only at runtime

Raktera contains trusted public verification material. The private signing key is not required by normal Classic or Pro builds.

03

No recurring activation

A valid Pro license is verified locally without a recurring server check or expiration timer.

04

Falls back to Classic capabilities

A missing or invalid Pro license affects Pro capabilities, not the encryption of the Raktera vault.

Security boundaries

What Raktera protects — and what still requires care.

Encrypted vault files

The normal .rkt vault is encrypted. Keep your Master Password private and protect any keyfile used by the vault.

Plaintext exports

JSON and CSV export functions intentionally create unencrypted output after credential verification. Treat exported files as sensitive data.

Device security still matters

Local encryption does not replace normal operating-system security, trusted software, backups, and physical device protection.

Raktera security

Local control backed by explicit cryptographic design.

AES-256-GCM vault encryption, Argon2id key derivation, optional keyfiles, and cryptographically separate offline Pro licensing.



Raktera Pro

Who is this license for?

Enter the name that should identify your Raktera Pro license. This will be associated with the order for license fulfillment.

Payment details and your checkout email are collected separately by Paddle.