Passphrase + Biometric Vault

Your Documents.
Truly Secure.

AstraVault locks your government IDs, PAN, passports, and medical records behind your vault passphrase and fingerprint biometrics — then encrypts everything with AES-256-GCM before it ever reaches the cloud.

AES-256-GCM Encrypted Privacy-First Design Zero-Trace Protocol Made in India
9:41 ●●● A AstraVault PRO 🔍 ⚙️ 📦 VAULT INVENTORY 🪪 National ID Card Identity › ID Documents Encrypted · 0.84 MB Added: 02 Jan 2026 📄 Bank Statement Mar 26 Financial › Bank Statements Encrypted · 2.10 MB Added: 15 Mar 2026 🏥 Health Insurance Policy Medical › Insurance Encrypted · 1.56 MB Added: 20 Feb 2026 💳 PAN Card Identity › ID Documents Encrypted · 0.62 MB Added: 28 Dec 2025 📷 ⬆️
600K PBKDF2 Iterations
SQLCipher Database
Passphrase + Biometric Unlock
Zero Plaintext on Disk
Android Keystore Hardware Key
Enterprise-grade protection

Security you can
actually verify.

Every document goes through a multi-layer encryption pipeline before it ever leaves your device. No exceptions.

🔐

Passphrase + Fingerprint Unlock

Your vault passphrase is the cryptographic root — fingerprint biometrics (via Android BiometricPrompt) provide fast daily unlock. Passphrase is always the fallback.

🔑

600K PBKDF2 Key Derivation

Your passphrase is stretched through 600,000 PBKDF2-SHA256 iterations before deriving the SQLCipher key. Brute-force is computationally infeasible.

💾

Hardware-Bound Android Keystore

The AES-256-GCM master key lives inside the secure hardware enclave and cannot be exported — it never leaves your device.

☁️

Encrypted-Only Cloud Storage

Documents are encrypted in RAM, then uploaded directly to your private Google Drive. Plaintext bytes are zeroed immediately after encryption.

// AstraVault Encryption Pipeline

STEP 1 — Identity Verification
  ✓ Fingerprint (Android BiometricPrompt)
  ✓ Vault passphrase (fallback)

STEP 2 — Key Derivation
  passphrase → PBKDF2-SHA256
  iterations: 600,000
  → SQLCipher DB key (256-bit)

STEP 3 — Document Encryption
  algorithm: AES-256-GCM
  key source: Android Keystore (HW)
  plaintext_bytes.fill(0x00) ✓

STEP 4 — Storage
  destination: user's Google Drive
  local_plaintext_on_disk: NONE

STATUS: VAULT SECURED ✓
What's inside

Everything your
documents deserve.

Smart OCR, intelligent categorization, 4-gate camera — built for the way real people manage critical documents.

🧼

Zero-Trace Capture

Documents are encrypted in RAM before any I/O. Plaintext never hits your phone's storage. The Zero-Trace Protocol runs at the hardware level — no temp files, no cache leaks.

📷

4-Gate Smart Camera

Real-time Blur, Luminance, Stability, and Aspect gates reject poor-quality frames automatically. Every scan is sharp and complete before capture is accepted.

🧠

Smart OCR + 18 Categories

ML Kit reads Latin and Devanagari text on-device, auto-categorizing across 18 document types — medical, legal, financial, identity, vehicle, property, and more.

🎭

Adaptive Entity Masking

Government IDs, PAN numbers, bank account numbers, and other sensitive identifiers are automatically detected and masked before any storage. Privacy is the default.

🛡️

Remote Kill-Switch

Lost your device? Trigger a remote wipe of all local secrets and databases via FCM — severing vault access permanently within seconds, from anywhere.

☁️

Private Drive Sync

Encrypted documents sync to your own Google Drive. AstraSoft never sees your data — it's your Drive, your keys, your vault. Retrieve from any device anytime.

Simple process

Secure in
three steps.

1

Sign In & Authenticate

Sign in with Google, then unlock with fingerprint biometrics or your vault passphrase. Your passphrase is set on first use and is the cryptographic root of your vault.

2

Capture or Import

Photograph documents with the 4-gate camera or import PDFs. OCR extracts text on-device, AI assigns the category — all private, all local.

3

Encrypted & Synced

Every document is AES-256-GCM encrypted in RAM, then synced to your private Google Drive. Access it on any device, whenever you need it.

Made for Bharat

India-First
Document Security.

Built from the ground up for Indian documents and Indian languages — with Devanagari OCR and privacy-first design baked in.

18

Document categories including national IDs, tax records, voter cards

2

Languages — English and Hindi (हिन्दी)

Private

Privacy-first, zero-access document storage

🪪

Sensitive ID Auto-Masking

OCR automatically detects 12-digit national ID patterns and masks the first 8 digits before any storage — protected by design.

💳

PAN Card Detection

Automatic PAN pattern recognition with selective field masking. Financial identity protected at capture time, not as an afterthought.

🔤

Devanagari OCR

ML Kit reads Hindi and Devanagari script documents natively — bank statements, certificates, and official records in your language.

⚖️

Privacy by Design

Data minimization, zero third-party analytics on documents, and full user data deletion support — privacy is a core architectural principle, not an afterthought.

Pricing

Simple, honest
pricing.

One-time purchase. No subscriptions. No hidden fees. Your vault works forever.

Standard
₹0
Free forever

  • 25 encrypted documents
  • Passphrase + biometric unlock
  • 4-Gate smart camera
  • Google Drive sync
  • Smart OCR + categorization
  • Unlimited capacity
  • Full audit trail
Get Started Free
Family / Team
Coming Soon
Zero-knowledge isolation

  • Shared subscription benefits
  • Multi-account isolation
  • Emergency cross-access
  • Secure identity recovery
FAQ

Common
questions.

How does vault unlock work?

AstraVault uses fingerprint biometrics for fast daily unlock and your vault passphrase as the cryptographic fallback. Your passphrase is set once and stored in Android's EncryptedSharedPreferences — it is never transmitted to any server.

What happens if I forget my passphrase?

AstraVault is zero-knowledge. Without your passphrase, nobody — including AstraSoft — can access your encrypted vault. Write your passphrase down and store it safely offline. There is no recovery option.

Where is my data stored?

Encrypted document files live in your own private Google Drive. Only encrypted metadata (category, filename, OCR snippet ≤500 chars) lives locally in the SQLCipher database. Plaintext never touches disk.

How do Ad Boosts work?

Watch an optional 30-second ad to unlock +5 additional document slots for the day. This is entirely optional and can be repeated as needed — your vault access is never gated by ads.

Does AstraVault work offline?

Yes. Already-synced documents are available offline through the encrypted local database. New captures are queued and synced to Drive automatically when connectivity resumes — no data is ever lost.

What security primitives does AstraVault use?

AES-256-GCM via Android Keystore hardware enclave, SQLCipher for the local database, PBKDF2-SHA256 with 600,000 iterations for key derivation, and Android BiometricPrompt — all industry-standard, auditable primitives.

Lock Down Your
Documents Today.

Join users who've moved their government IDs, tax documents, medical records, and financial documents into an encrypted vault nobody else can open.

Free on Google Play