
MFA authenticator
TOTP codes for any service that supports authenticator-app TOTP — generated locally, opened only by you.
Keep MFA codes, passwords and secure notes in one app, unlocked by your face. There is no master password. The app derives the key on-device and discards it after use; biometric images and plaintext templates are not stored.
Unlocked by you.
TOTP codes for any service that supports authenticator-app TOTP — generated locally, opened only by you.

All your logins in a biometric-locked vault — no master password to remember or leak.

API keys, seed phrases, and private documents, encrypted at rest and unlocked only by your scan.
A quick biometric scan generates a cryptographic key on-device, in real time.
The key decrypts your codes, passwords, and notes locally — their plaintext is not sent to a server.
The derived key is discarded after use. The encrypted vault and sealed recovery data remain.
ML-KEM and ML-DSA — NIST FIPS 203 and 204 — so your data stays protected as computing power advances.
We have no ability to read your passwords, messages, or notes. The server is mathematically blind to your content.
Your scan generates a key on-device and discards it. Biometric images and a plaintext template are not transmitted or saved; sealed recovery data is retained.
Error-correcting codes keep a beard, glasses, makeup, lighting, or years of aging within tolerance — re-deriving the exact same key, with no stored template to update.
Protected content requires a live scan to unlock. No PIN fallback, no master password. This does not guarantee protection after an endpoint is compromised.
An encrypted backup only your biometric can unlock restores your vault on a new phone — no passwords to transfer.
Free on iOS and Android. No master password, ever.
Looking for encrypted messaging?Meet Chat in Lume Auth