Proton's vault is expanding. What does that mean for personal data?

A password manager that also holds passkeys, identities and seed phrases is not a password manager any more. It is a personal data vault with a different name on the door, and the company shipping it has an audit, a brand, and a user base none of the projects in this category can match.

What is actually being assembled

Four things, each ordinary on its own.

An encrypted vault holding logins, notes, cards and identities. Passkey support on free and paid plans, which puts the authentication credential itself in the vault. Import of self-custodial keys and seed phrases, which puts key material in there too. And an independent audit, run between January and April 2026 by a firm with no financial ties, finding no remote exploits and no encryption bypasses.

Put together, that is most of a personal identity store. What it lacks is a credential format anybody else can verify, and a story for presenting a claim to a third party without handing over the underlying data.

Why that matters more than the feature list

The hard problem in this category was never the vault. Encrypting a blob and syncing it is well understood. The hard problem is adoption: getting enough people to keep their data somewhere they control that applications find it worth reading from.

A company with an existing base does not have that problem. It has the users already, and adding a credential layer is an engineering decision rather than a market-creation exercise.

Nothing says they will. The point is that they could, and the sequence above is what it would look like early.

What this means for us, stated against ourselves

It means the incumbent path to user-controlled personal data does not run through us.

We have no audit. They completed one this year. They have a business. If the category is won by whoever already holds the users, the outcome is decided somewhere we are not standing.

Saying so is not a risk. A page that reported a well-capitalised, audited incumbent moving toward our axis and then explained why it does not matter would be worth less than nothing, because the reader would correctly stop believing the rest of the estate.

What a pod still answers that a vault does not

A vault is a container you own. It is not a protocol other people's applications read from.

The distinction is the same one that runs through this whole surface. Access control is about which agent may do what to a particular resource, enforced on every request, by a server anybody can run. A vault's answer is that you export something and paste it somewhere.

That difference is real and it is also small next to a hundred million users. We are not going to inflate it.

What our own brief got wrong

It dates passkey support to February 2026. Public material puts it at March 2024. It also names a wallet product this check did not find, and it carries user and customer counts we could not corroborate.

None of those is printed above. This is the fifth failure of a fact in our own competitor notes across two runs, and the lesson is the same each time: a secondhand record about another company is a hypothesis, not a source.

Keep reading

Proton's vault is expanding. What does that mean for personal data? · Solidus