# PaperVault privacy rating

Encrypts secrets into a printable paper vault and splits the decryption key into several paper key cards with Shamir secret sharing. It runs in the browser, as a standalone offline app or from the command line.

## Summary

PaperVault scores 75 out of 100 (grade B) on the password managers criteria. It meets 7 of 11 criteria: open source, no trackers or telemetry, no ads or data sales, TLS configuration, end-to-end encrypted vault, local or self-hosted option and full export. It partly meets security headers. It does not meet independent audit, transparency report and tells users about requests. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.

- Website: https://papervault.xyz
- Source code: https://github.com/boazeb/papervault
- License: MIT
- Home page trackers: none found
- Category: [Password managers](https://privacyratings.com/password-managers/)
- Grade: B (75/100)

## Criteria

| Criterion | Answer | Note | Evidence |
| --- | --- | --- | --- |
| Open source | Yes | MIT. | https://github.com/boazeb/papervault/blob/main/LICENSE |
| No trackers or telemetry | Yes | No telemetry or analytics in the source code, and the website loads no third-party scripts. | https://github.com/boazeb/papervault/blob/main/package.json |
| No ads or data sales | Yes | Free open source tool with no ads or paid tiers. | https://github.com/boazeb/papervault#readme |
| Independent audit | No | No independent audit is published. |  |
| Transparency report | No | No transparency report or government request policy is published. |  |
| Tells users about requests | No | No published policy on notifying users about data requests. |  |
| TLS configuration | Yes | Grade A+ | https://www.ssllabs.com/ssltest/analyze.html?d=papervault.xyz&hideResults=on |
| Security headers | Partial | Grade B+ (80/100+) | https://developer.mozilla.org/en-US/observatory/analyze?host=papervault.xyz |
| Modern web standards | Not tested yet | Not tested yet. |  |
| End-to-end encrypted vault | Yes | Local-only: secrets are encrypted in the browser and the key is split into printed shards, with no sync service. | https://github.com/boazeb/papervault#-overview |
| Local or self-hosted option | Yes | Vaults are kept on paper or local media, and the app can be self-hosted or run offline. | https://github.com/boazeb/papervault#-self-hosted-web-app-recommended-for-maximum-security |
| Full export | Yes | Vaults and keys are printed or saved to digital media, and any PaperVault instance can unlock them. | https://github.com/boazeb/papervault#-quick-start |

Source: https://privacyratings.com/password-managers/papervault/
Edit: https://github.com/privacyratings/privacyratings.com/edit/main/ratings/password-managers/papervault.md
