Envryn
.env files get committed, copied and left behind. Cloud secrets managers fix that by asking you to trust another company with the keys. Envryn keeps an encrypted vault on your own devices and syncs Windows and Android directly over the local network, with no account and no relay server.
- Type
- Security tool
- State
- Beta · v0.1.9
- Role
- Solo, end to end
- Rust
- Tauri
- React
- TanStack Router
- XChaCha20-Poly1305
- Argon2id

At a glance
- Rust core; the UI is treated as untrusted
- Windows and Android sync with no server in between
- CodeQL, Semgrep, Gitleaks, cargo-audit and fuzzing in CI
What I owned
Solo project. The Rust vault core and cryptography, the Tauri shell, the React interface, the Android build, the paired-device sync protocol, and the CI security tooling around all of it.
Decisions, and what they cost
The interface is treated as untrusted
A webview UI is the easiest place for a bug to leak a secret, so it never gets to decide anything. Sensitive operations cross a typed Tauri boundary and are enforced by the Rust core, and the TypeScript bindings are generated from the Rust IPC types so the two sides cannot drift apart. The optional local AI worker runs as a separate process and receives only the minimum sanitized input for the operation it was asked to do.
What I gave upEvery feature touches three places: a Rust command, the generated contract, and the UI. That is slower to build than letting the interface read the vault directly, and it is the reason the UI can be wrong without being dangerous.
Direct device sync instead of a hosted relay
Devices pair with a code a human compares on both screens, then sync encrypted records over mutually authenticated TLS on the local network. Nothing sits in the middle, so there is no server holding ciphertext, metadata or an account list.
Where your secrets travel between devices Cloud secrets manager (not used)
DeviceVendor's serverDeviceSomeone else holds the ciphertext, the metadata and the account list.
Envryn
WindowsMutual TLS, local networkAndroidPaired with a code you compare on both screens. Nothing in the middle.
What I gave upSync only happens when both devices are on the same network. There is no cloud fallback to reach for when you are away from home, because adding one would bring back the thing Envryn exists to avoid.
Separate keys for separate jobs
The master password goes through Argon2id, records are sealed with XChaCha20-Poly1305, and HKDF-SHA256 derives domain-separated subkeys so a key made for one purpose is never reused for another. On Windows, DPAPI and Windows Hello add optional platform protection on top.
What I gave upThere is no account, so there is no account recovery. Lose the master password and nobody, including me, can open the vault. Encrypted backups are the answer to that, not a reset link.
Known limitations
- Windows installers do not have a trusted publisher signature yet, so SmartScreen warns. Every release carries CHECKSUMS.txt to verify against.
- Android has less physical-device coverage than Windows.
- No automatic updater in the 0.1.x series; you install a newer build over the old one.
- It has had an internal security review, not an independent audit, and the README says so.
Where it stands
Public beta. Windows .exe and .msi installers plus a universal Android APK, each release shipping checksums and a CycloneDX SBOM. CI runs unit, integration and fuzz targets alongside CodeQL, Semgrep, Gitleaks, OSV-Scanner, cargo-audit and cargo-deny. It imports .env content, detects common credential formats offline, and clears copied secrets after a delay.
