Browse the directory.
After authentication: item names, types, and public login metadata.
SECURITY / THE RELEASE BOUNDARY
ByzanPass is designed for a computer you cannot fully trust. The device decides which individual record may leave the vault.
After authentication: item names, types, and public login metadata.
Stored identity, a fresh PIN, and a physical approval.
The selected record is now exposed to the computer.
WHAT IS ENFORCED
Private records are encrypted independently. Firmware validates the selected entry and presents its stored identity before release. The app protocol provides no bulk plaintext-read command.
An already unlocked vault still requires a fresh device PIN for each new entry reveal. A previously approved view can remain visible until it closes or reaches the user’s configured timeout. The computer can retain anything it has already received.
Authenticating through the extension authorizes computer access. Local browsing requires the master password entered on the Trezor itself. PIN entry and USB reconnection do not grant that local mode.
The microSD card holds encrypted directory and record files. Password-vault recovery requires both a complete encrypted backup and its 12 recovery words. Words alone do not contain the records.
Pairing and fresh signed statements bind the connection to the expected device and state. A detected firmware change requires explicit approval with the master password. These checks do not independently prove that replacement firmware is trustworthy.
WHAT STILL MATTERS
Malware can capture released plaintext, monitor typing, alter a website, or read public directory metadata after authentication. Check the identity on the device before approving. Closing a view cannot erase a copy taken by a compromised host.
Malicious firmware could bypass the approval policy. A matching hash is a consistency check, not an independent security audit or a substitute for authenticated software distribution.
Keep the device locked when unattended. Protect its PIN and master password. Someone with both the complete backup and recovery words can recover the vault independently of the original device.
Restoring a complete older backup restores older records. The format cannot prove that an external backup is the newest copy. Passkeys and security-key credentials are device-only and not restored with the password vault.
HARDWARE DIFFERENCES
| Capability | Safe 5 | Model T |
|---|---|---|
| Touchscreen approval & fresh reveal PIN | Yes | Yes |
| Encrypted microSD vault | Yes | Yes |
| Secure-element PIN protection | Yes | No secure element |
| Haptic feedback | Yes | No |
| Factory authenticity after custom unlock | Permanently removed by bootloader unlocking | No Safe 5 authenticity path |
The separate Safe 5 secure-element master-password attempt limiter is not enabled in the current development candidate.
DEVELOPMENT ALPHA
Review the current implementation and remaining release requirements.