ByzanPass. Get started

A password manager with a physical boundary

Your passwords.
Your device.
Your say.

Turn your Trezor into a password vault. Browse your logins in Chrome. Release a password only when you approve that specific entry on the device.

Trezor Safe 5 & Model T / Chrome extension

Development alpha For testing with dummy passwords. See release status.

ONE REQUEST. ONE DECISION.DIRECT USB
YOUR COMPUTER
ByzanPassConnected
My vault3 entries
MPersonal mailProtected · ••••••••▣
FFile storageProtected · ••••••••▣
Atlas password••••••••••••Private values stay protected
YouRequest one login
USB
↔
YOUR TREZOR
ByzanPass
VAULT READYSecrets stay here.
Website
atlas.example
Account
alex@example.test

Local browsing needs its own master-password unlock.

Safe 5 / Model T
Encrypted microSD vaultAll other records stay protected
01 / FINDFind the login you need.

Directory access lets you find entries. It does not release their passwords.

Illustration · fictional data · no device accessAll situations ↗

Encrypted on your microSD One entry per approval Direct USB in Chrome

01 / HOW IT WORKS

An open vault.
A closed door to its secrets.

Finding an entry and revealing its password are separate actions. The important decision happens in your hand.

01

Find your login.

Authenticate to see your directory: names, websites, and public login details. Select the entry you need.

02

Check your device.

The Trezor shows the stored identity of that entry. Physically approve or deny the request. Optional entry protections can also require PIN or master-password re-authentication.

03

Use one password.

The extension receives that approved record. Opening another entry requires another approval on the Trezor.

Play the approval, denial and recovery flows

A compromised computer can capture a password you release to it. The physical approval boundary is designed to prevent it from silently reading the rest of your vault. Understand the security model ↗

02 / IN YOUR HANDS

A vault you
can hold.

Your encrypted password database lives on the microSD card in your Trezor. The extension is your interface to it.

  • ↗ Browse and fill logins in Chrome.
  • ↗ View passwords on the device after a separate on-device master-password unlock.
  • ↗ Back up encrypted files and keep recovery words separately.
Explore backup & recovery

03 / EVERYDAY DETAILS

A familiar vault.
A different release boundary.

The conveniences of a password manager, with approval enforced by the firmware on your device.

Logins where you need them

Find matching accounts in the extension and approve an entry before filling it on a website.

More than passwords

Keep secure notes, recovery codes, payment cards, and other private fields in individually encrypted records.

No Bridge for Chrome

The Chrome package communicates directly over USB. No native host or Trezor Bridge is needed.

Choose your viewing timeout

Automatically hide sensitive information after 1–1,440 minutes, or keep it visible until its view is closed or refreshed.

Bring your existing logins

Preview imports from supported exports, including Bitwarden, 1Password, KeePass, LastPass, and browser CSV files.

A clear view of your accounts

Website icons and public login details help you find the right entry. Favicons are handled by the extension.

04 / CHOOSE YOUR DEVICE

Two devices.
The same deliberate approval.

ByzanPass uses custom firmware and an encrypted microSD vault. Guided Chrome setup covers both models.

SUPPORTED DEVELOPMENT TARGET

Trezor Safe 5

Touchscreen approval, haptic feedback, and secure-element PIN protection.

Safe 5 setup
SUPPORTED DEVELOPMENT TARGET

Trezor Model T

Touchscreen approval and encrypted microSD storage, without a secure element.

Model T setup

Use a dedicated device. The ByzanPass firmware disables cryptocurrency wallet commands. Safe 3 and Safe 7 setup are not supported.

05 / GOOD QUESTIONS

Before you plug in.

Does unlocking the extension unlock passwords on the Trezor too?

No. Computer access and local device access are separate. To browse passwords directly on the Trezor, enter the master password on the device. Every new local reveal requires a fresh PIN. Normal Chrome reveals need a device tap. Optional protections can require PIN or master-password re-authentication for selected entries, and a global hourly allowance can require PIN after a chosen number of successful Chrome reveals.

What if my computer is compromised?

It can read public metadata after authentication and capture anything you approve for release to it. It can also mislead you or interrupt a request. Always check the entry on the device. The design does not provide a bulk plaintext-read command for the vault.

Can I recover if I lose the device?

Password-vault recovery requires a complete encrypted card backup and its 12 recovery words. Enter those words only on the replacement device. Passkeys and security-key credentials are device-only and are not restored from the password-vault backup. Read the recovery guide.

Does it work without a native host?

The Chrome WebUSB package connects directly to the device. Firefox is a separate integration and is not part of this direct USB setup guide.

Can I use my current cryptocurrency wallet device?

Use a dedicated device. Changing firmware can wipe existing storage, and ByzanPass firmware disables wallet commands. Safe 5 bootloader unlocking is permanent and removes factory authenticity keys. Review the model-specific setup before proceeding.

Is ByzanPass ready for my real passwords?

It is a development alpha. Use dummy credentials while full physical acceptance, independent security review, and authenticated production distribution remain release requirements. See development status.

YOUR NEXT STEP

Make the device
part of the decision.

New vault, new computer, or restoring a backup?
Start with the path that fits you.

Open the setup guide