How It Works

From organizing in a visual dashboard to encrypting and storing your data - see exactly how Hexbon works at every step.

What is Hexbon?

Hexbon is a simple, private way to store all your sensitive information in one place. Think of it as a vault where you control everything.

You structure your data however you need - passwords, notes, credentials, or anything else. We provide the secure storage. You keep the keys.

Encrypted on your browser

Data is locked with your master password before leaving your device.

We never have access

We store encrypted data. Without your password, it's meaningless to us.

Your data, your control

Create custom fields, organize as you like, and manage everything yourself.

1

Structure Your Data

Create records with custom fields for passwords, notes, credentials, or whatever you need to store securely.

2

Encrypt Locally

Your browser locks everything with your master password before it leaves your device - nothing unencrypted ever travels to our servers.

3

Store Safely

Your encrypted data lives in our database, protected by your password. Access it anytime from any device.

Easy To Organize

See how your data is displayed in the dashboard. Each field type has a dedicated visual representation for easy management.

Login Credentials
Website
https://example.com/login
Username
johndoe
Email
john@example.com
Password
••••••••••••••••
2FA
847 291
18s
Notes
Recovery phone: +1 555-1234

Supported Field Types

Link / URL

Clickable hyperlinks that open in a new tab

Username

User identifiers and login names, displayed as plain text

Email

Email addresses, displayed as plain text with copy functionality

Secret / Password

Sensitive data hidden by default, revealed on click with toggle visibility

TOTP (2FA)

Time-based one-time passwords with live countdown timer

Note

General text information, displayed as plain text

Behind The Scenes

Your data is organized in a clean hierarchical format before encryption. This structure allows for flexible organization of sensitive information.

Structure Overview

Cards

Top-level containers for organizing related records into categories

Records

Individual entries within a card, each representing a distinct item

Data (Sections)

Named groups of values within a record for logical organization

Values

The actual content items with their display value and type

Field Types

Each value has a type that determines how it is displayed:

username email secret totp link note
Timestamp

Unix timestamp for tracking when the card was last updated

Behind the scenes
{
  "cards": [
    {
      "title": "Accounts",
      "records": [
        {
          "title": "Gmail",
          "data": [
            {
              "name": "Login",
              "values": [
                {
                  "value": "https://gmail.com",
                  "type": "link"
                },
                {
                  "value": "john@gmail.com",
                  "type": "email"
                },
                {
                  "value": "P@ssw0rd!2025",
                  "type": "secret"
                },
                {
                  "value": "JBSWY3DPEHPK3PXP",
                  "type": "totp"
                },
                ...
  ]
}

Encryption Format

Encrypted data follows a structured format that includes version information, cryptographic parameters, and the ciphertext. This enables backward compatibility and future algorithm upgrades.

Encrypted Output
v2:kJx3mN9pQ2rT5wY8zB1cD2eF:aB1cD2eF3gH4iJ5k:L7mN8oP9qR0sT1uV2wX3yZ4aB5cD6eF7gH8iJ9kL0mN1oP2qR3sT4uV5wX6yZ7aB8cD9eF0gH1iJ2kL3mN4oP5qR6sT7uV8wX9yZ0aB1cD2eF3gH4iJ5kL6mN7oP8qR9sT0uV1wX2yZ3aB4cD5eF6gH7iJ8kL9mN0oP1qR2sT3uV4wX5yZ6aB7cD8eF9gH0iJ1kL2mN3oP4qR5sT6uV7wX8yZ9aB0cD1eF2gH3iJ4kL5mN6oP7qR8sT9uV0wX1yZ2aB3cD4eF5gH6iJ7kL8mN9oP0qR1sT2uV3wX4yZ5aB6cD7eF8gH9iJ0kL1mN2oP3qR4sT5uV6wX7yZ8aB9cD0eF1gH2iJ3kL4mN5oP6qR7sT8uV9wX0yZ1aB2cD3eF4gH5iJ6kL7mN8oP9qR0sT1uV2wX3yZ4aK2mR7xP3qS9wL5nV8yB1dF4jH6oT0uC2eG5iM8kQ1sW4zX7aD0gJ3lO6pR9tY2bE5hN8mP1qU4vZ7cF0iL3nS6wA9dH2jK5oT8xB1eG4mQ7sV0yC3fI6lP9rU2wZ5aE8hN1kR4tX7bD0gM3jO6qS9vY2cF5iL8nP1uW4zB7eH0kQ3sT6xA9dG2jM5oR8tY1bE4hN7mP0qU3vZ6cI9lO2wS5aD8gK1nT4xB7eH0kQ3sU6yA9dF2jM5oR8tV1bE4hN7mP0qW3zC6iL9lO2wS5aD8gK1nT4xB7eH0kR3sU6yA9dF2jM5oQ8tV1bE4hN7mP0qW3zC6iL9nO2wS5aD8gK1kT4xB7eH0jR3sU6yA9dF2mM5oQ8tV1bE4hN7nP0qW3zC6iL9kO2wS5aD8gJ1nT4xB7eH0mR3sU6yA9dF2jK5oQ8tV1bE4hN7lP0qW3zC6iM9nO2wS5aD8gK1kT4xB7eH0jR3sU6yA9dF2mL5oQ8tV1bE4hN7nP0qW3zC6iK9lO2wS5aD8gJ1nT4...

Format Structure

Version

Encryption version identifier (current version is v2)

Salt

Base64-encoded 128-bit random salt

IV

Base64-encoded 96-bit initialization vector

Ciphertext

Base64-encoded encrypted data with auth tag

Native browser cryptography

All cryptographic operations use the Web Crypto API, a low-level interface provided by modern browsers for performing cryptographic operations.

Benefits of WebCrypto

  • Hardware-accelerated performance
  • Constant-time implementations prevent timing attacks
  • Key material can be marked as non-extractable
  • No external JavaScript dependencies
  • Audited and maintained by browser vendors

Browser Compatibility

Supported in all modern browsers: Chrome, Firefox, Safari, Edge, and their mobile counterparts.

crypto.js
// Derive AES key from password
const keyMaterial = await crypto.subtle
  .importKey(
    'raw',
    encoder.encode(password),
    'PBKDF2',
    false,
    ['deriveBits', 'deriveKey']
  );

const aesKey = await crypto.subtle
  .deriveKey(
    {
      name: 'PBKDF2',
      salt: salt,
      iterations: 600000,
      hash: 'SHA-256'
    },
    keyMaterial,
    { name: 'AES-GCM', length: 256 },
    false,
    ['encrypt', 'decrypt']
  );

// Encrypt with AES-GCM
const ciphertext = await crypto.subtle
  .encrypt(
    { name: 'AES-GCM', iv: iv },
    aesKey,
    plaintext
  );

Version History

Hexbon stays aligned with industry security standards while preserving backward compatibility and allowing seamless, easy migration.

v2

Version 2 (v2)

Current standard

PBKDF2 with 600,000 iterations (OWASP 2025 recommendation). All new encryptions use v2. v1 data is automatically upgraded to v2 when you save changes - no manual input required.

600,000 iterations PBKDF2-SHA256 AES-256-GCM
v1

Version 1 (v1)

Original release

PBKDF2 with 150,000 iterations. Still supported for decryption of existing data.

150,000 iterations PBKDF2-SHA256 AES-256-GCM

Ready to secure your data?

Create your free account and experience truly private data storage.

Get Started Free

We barely use cookies

We only use strictly necessary cookies, that enhance website security and improve user experience. We don't track your actions or activity.