Skip to content

Coralesoft/CoraleVault

Folders and files

NameName
Last commit message
Last commit date

Latest commit

ย 

History

23 Commits
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 

Repository files navigation

CoraleVault

Open-source password manager with military-grade encryption.

๐Ÿ”’ Your passwords, encrypted on your device. No cloud. No subscriptions. No tracking.

License: GPL v3 Platform Release C++17


Download Official Releases

Pre-built, cryptographically signed releases:

โžก๏ธ Download CoraleVault

Available for:

  • โœ… Windows 7, 8, 10, 11 (64-bit)
  • โœ… macOS 10.13+ (Intel & Apple Silicon)
  • โœ… Linux (Debian, Ubuntu, Fedora, AppImage)

All releases are GPG signed for security verification.


About CoraleVault

CoraleVault is a desktop password manager focused on security, privacy, and simplicity.

Core Principles

๐Ÿ”’ Security First

  • AES-256-CBC encryption with HMAC-SHA256 authentication
  • PBKDF2 key derivation (600,000 + iterations - OWASP 2025 compliant)
  • Memory protection against RAM dumps
  • Rate limiting against brute-force attacks
  • Zero-knowledge architecture

๐Ÿ  Privacy by Default

  • No cloud synchronization (your data never leaves your device)
  • No telemetry or tracking
  • No account required
  • No company can access your data

๐Ÿ†“ Free Forever

  • Open source (GNU GPL v3.0)
  • No subscriptions or premium tiers
  • No advertisements
  • All features included

๐Ÿ” Transparent & Auditable

  • Full source code available for security review
  • No backdoors, no hidden tracking
  • Community-driven development

Features

Current Release

  • ๐Ÿ” Strong Encryption - AES-256 with HMAC-SHA256 authentication
  • ๐Ÿ”‘ Password Generator - Cryptographically secure random passwords
  • ๐Ÿ“‹ Clipboard Auto-Clear - Passwords automatically cleared after 30 seconds
  • ๐Ÿ” Fast Search - Quickly find any password
  • ๐Ÿ“‚ Group Organization - Organize passwords into categories
  • ๐Ÿ“ฅ Import/Export - CSV import from Chrome, Bitwarden, and other managers
  • ๐Ÿ’พ Local Storage - Your vault file, under your control
  • ๐Ÿ–ฅ๏ธ Cross-Platform - Windows, macOS, and Linux

Coming Soon

  • โ˜๏ธ Optional Cloud Sync - Self-hosted or managed sync service
  • ๐Ÿ“ฑ Mobile Apps - iOS and Android
  • ๐ŸŒ Browser Extensions - Chrome, Firefox, Safari, Edge
  • ๐Ÿ‘ฅ Vault Sharing - Share passwords with family or team (encrypted)

Security

Encryption Standards

CoraleVault meets or exceeds industry standards:

NIST Compliance:

  • โœ… NIST SP 800-132 (Password-Based Key Derivation)
  • โœ… NIST SP 800-38A (Block Cipher Modes - AES-CBC)
  • โœ… NIST SP 800-108 (Key Derivation - HKDF)
  • โœ… FIPS 197 (Advanced Encryption Standard)
  • โœ… FIPS 198-1 (HMAC)

OWASP Compliance:

  • โœ… OWASP ASVS v4.0 Section 6 (Cryptographic Verification)
  • โœ… OWASP Password Storage Cheat Sheet (2025)
  • โœ… OWASP Top 10 Protection

Why Open Source Matters

Open source allows security researchers to verify there are no:

  • โŒ Backdoors or hidden data collection
  • โŒ Weak encryption implementations
  • โŒ Security vulnerabilities
  • โŒ Privacy violations

Trust through transparency.


Installation

Windows

Installer (Recommended):

  1. Download CoraleVault-Setup.exe from releases
  2. Run the installer
  3. Launch CoraleVault from Start Menu

Portable Version:

  1. Download CoraleVault-Portable.zip
  2. Extract anywhere (USB drive, cloud folder, etc.)
  3. Run CoraleVault.exe

macOS

  1. Download CoraleVault.dmg from releases
  2. Open the DMG file
  3. Drag CoraleVault to Applications folder
  4. Launch from Applications

Linux

Debian/Ubuntu (.deb):

sudo dpkg -i coralevault_*.deb

Fedora/RHEL (.rpm):

sudo rpm -i coralevault-*.rpm

AppImage (Universal):

chmod +x CoraleVault-*.AppImage
./CoraleVault-*.AppImage

Verifying Downloads

All releases are cryptographically signed with GPG.

Quick Verification:

# Import the public key
gpg --import GPG-PUBLIC-KEY-CORALEVAULT.asc

# Verify a download
gpg --verify CoraleVault-Setup.exe.asc CoraleVault-Setup.exe

Expected Output:

gpg: Good signature from "CoraleSoft (CoraleVault Official Releases) <releases@coralesoft.nz>"

GPG Key Fingerprint:

844D CFC4 4A5D E9C1 4C3A  2F62 497A 4CFB B700 543E

Quick Start

First Time Setup

  1. Launch CoraleVault
  2. Create New Vault
    • Choose a strong master password (12+ characters)
    • Write it down! There's no password recovery
  3. Add Your First Password
    • Click "Add Entry"
    • Fill in website, username, password
    • Save
  4. Lock Your Vault when done (Ctrl+L / Cmd+L)

Best Practices

Choose a Strong Master Password:

  • โœ… 12+ characters minimum
  • โœ… Mix of letters, numbers, symbols
  • โœ… Memorable but not obvious
  • โœ… Not used anywhere else

Examples of strong passwords:

  • MyDog&2Cats!Love2025
  • correct-horse-battery-staple
  • ILived@123MainSt_Until1995!

Back Up Your Vault:

  • Your vault is stored as a .vault file
  • Copy it to USB drive, external hard drive, or cloud storage
  • The file is encrypted, so cloud storage is safe

Documentation


Roadmap

Current (v2025.11.5)

  • โœ… Desktop password manager
  • โœ… Local encryption
  • โœ… Import from Chrome, Bitwarden
  • โœ… Cross-platform (Windows, macOS, Linux)

Near Future (v2026.1.0 - Q1 2026)

  • ๐Ÿšง Self-hosted sync server (open source)
  • ๐Ÿšง Desktop sync support
  • ๐Ÿšง Conflict resolution

Medium Term (v2026.2.0 - Q2-Q3 2026)

  • ๐Ÿ”ฎ Browser extensions (Chrome, Firefox, Safari, Edge)
  • ๐Ÿ”ฎ Auto-fill for websites
  • ๐Ÿ”ฎ Cloud-hosted sync service (optional, subscription)

Long Term (2027+)

  • ๐Ÿ”ฎ Mobile apps (iOS, Android)
  • ๐Ÿ”ฎ Biometric unlock
  • ๐Ÿ”ฎ Hardware key support (YubiKey)
  • ๐Ÿ”ฎ Vault sharing (families, teams)

View full roadmap โ†’


Comparison

vs. Cloud Password Managers (1Password, LastPass, Dashlane)

Feature CoraleVault Cloud Managers
Price Free forever $3-10/month
Data Location Your computer Their cloud
Open Source โœ… Yes โŒ No
Self-Hosting โœ… Yes โŒ No
Vendor Lock-in โŒ None โœ… Yes
Internet Required โŒ No โœ… Yes

vs. Bitwarden

Feature CoraleVault Bitwarden
Price Free Free / $10/year
Desktop App โœ… Native C++ โœ… Electron
Performance โšก Fast โšก Good
Self-Hosting Coming Q1 2026 โœ… Yes
Mobile Apps Coming 2027 โœ… Yes
Browser Extensions Coming Q2 2026 โœ… Yes

Current Focus: Desktop-first, with sync and mobile coming soon

vs. KeePass

Feature CoraleVault KeePass
Modern UI โœ… Clean, native โŒ Dated
Cross-Platform โœ… Native on all โš ๏ธ Ports vary
Active Development โœ… Since 2020 โœ… Since 2003
Sync Built-in Coming Q1 2026 โŒ Manual
Browser Integration Coming Q2 2026 โš ๏ธ Plugins

Both are excellent! Choose CoraleVault for modern UX, KeePass for mature ecosystem.


Support

Need Help?

Contact


Contributing

CoraleVault is open source and welcomes contributions!

Ways to contribute:

  • ๐Ÿ› Report bugs
  • ๐Ÿ’ก Suggest features
  • ๐Ÿ” Security audits
  • ๐Ÿ“ Improve documentation
  • ๐Ÿ’ป Submit pull requests
  • ๐ŸŒ Translations

License

GNU General Public License v3.0 - See LICENSE for details.

What this means:

  • โœ… Free to use, modify, and distribute
  • โœ… Modifications must remain open source
  • โœ… No warranty (use at your own risk)
  • โœ… Commercial use allowed

For commercial licensing inquiries: releases@coralesoft.nz


Acknowledgments

CoraleVault is built with:

Special thanks to the open source community for making secure, private software possible.


Star History

If you find CoraleVault useful, please star the repository! โญ

It helps others discover the project and motivates continued development.


Copyright ยฉ 2020 - 2025 Coralesoft

Download โ€ข Documentation โ€ข Security โ€ข Website

Packages

No packages published

Languages