KeyGuard Password is now KeyCare Pass. Same vault, same account, a new name and address.

Know which passwords to change first

Vault health reports look through your vault for the passwords most likely to get you into trouble, and show you where to start.

Most account takeovers start with a password that was reused, guessed or leaked.

Five reports, one vault

Exposed passwords

Passwords found in known data breaches, checked without sending your passwords anywhere.

Reused passwords

The same password on several sites, so one breach opens many doors.

Weak passwords

Passwords that are short or easy to guess.

Unsecured websites

Logins saved with http:// addresses, which send your password unencrypted.

Inactive two-step login

Sites that offer two-step login where your login has no authenticator key.

How it works

Breached password check

Checked privately, by design

To see whether a password appears in a breach, your browser hashes it with SHA-1 and sends only the first five characters of the hash to the Pwned Passwords service. It compares the matching hashes on your device, so the password and its full hash never leave it.

Try the breached password checker

For organizations

The same reports for shared items

Owners and admins run the reports on the organization's collections from the Admin Console, to find shared logins that need a new password.

The Admin Console

Coming soon

  • Breach monitoring: an alert when your email addresses or your organization's domains appear in a new breach Coming soon

Frequently asked questions

Does KeyCare Pass send my passwords to check them?

No. Only the first five characters of a SHA-1 hash of each password leave your device, and many thousands of passwords share each prefix.

Which plans include the reports?

Every plan. Families, Teams and Enterprise members get them for their own vaults too.

Try it with your own passwords

Create your account, then choose the plan that fits.