Desktop App
Flowsta Vault
Your sovereign hub on your desktop. It runs Holochain locally so your keys never leave your computer — manage your identity, sign files with Sign It, and run third-party apps, with no one else holding the keys.
Free & open source · Linux, macOS and Windows · v0.7.0

What you can do
More than an identity manager
Your keys, your apps, your data — all on your own machine.
Sign your files with Sign It
Cryptographically sign any file — declare your rights, AI policy and authorship. Right-click from your OS file manager to sign without leaving where you are, and sign files up to 10 GB locally with no upload.
About Sign It →Run third-party apps — even offline
Vault runs a local Holochain conductor, so third-party apps live right beside your identity. Sign in to them with no internet at all — and you approve every connection.
Your data, encrypted and portable
Flowsta and the apps you connect store your data encrypted on your own machine — never a remote server. Export it all, keys included, whenever you want. No lock-in.
One identity, every device
Cryptographically link your desktop vault to your web account. Same identity in your browser, on your phone, and in Vault — all proven by you.
Get Started
Download Vault
Linux
Debian .deb
x86_64
macOS
Apple Silicon .dmg
Apple Silicon
Windows
Setup .exe
x86_64
Need a different build?
For other formats — Intel Mac (.dmg), Linux .rpm, Windows .msi — head to the v0.7.0 release on GitHub to see the full list of installers for this version.
Only ever download Flowsta Vault from the buttons above or directly from our GitHub releases page — never from anywhere else. Vault is where you enter your password and 24-word recovery phrase, and a tampered build could steal them and take control of your identity. No third-party mirror, app store, or download site is a safe source. If in doubt, always verify you're on github.com/WeAreFlowsta.
Comfortable with a terminal? Every release also ships a SHA256SUMS.txt so you can confirm your download matches what we published. If that doesn't mean anything to you, you don't need it — the download buttons above are all you need.
Setup
How It Works
Create your 24-word recovery phrase
Sign in to your Flowsta dashboard and generate a recovery phrase under Settings → Password. This phrase is the cryptographic seed for your identity — write it down and store it somewhere safe.
Download Vault
Grab the installer for your platform from the download section above, or the button in the hero. Linux, macOS and Windows are all supported — free and open source.
Install, sign in, and link
Open Vault, sign in with your Flowsta account, and enter your 24-word phrase. Your desktop identity is generated locally and automatically linked to your web account via a cryptographic attestation. No copy-pasting keys, no manual sync.
Sign files, connect apps, stay sovereign
Use Vault to sign files with Sign It, install third-party Holochain apps, and approve every connection. Vault auto-locks when you step away — your keys stay yours.
Features
What's Inside
The security and design choices under the hood — so your keys, and your data, stay yours.
Military-grade encryption
Your vault is encrypted with AES-256-GCM and your password is hashed with Argon2id — the same memory-hard scheme serious password managers rely on.
Zero-knowledge by design
Your recovery phrase and private keys are never stored unencrypted and never sent to a server. The key that signs as you lives in memory only while the vault is unlocked.
You approve every request
Apps must ask before they authenticate, link, or sign on your behalf. Choose which sites you trust, and revoke any connection at any time.
Auto-lock & system tray
A configurable inactivity timeout (5 minutes to never) locks the vault and clears your keys. Minimises to the system tray so it's there when you need it.
Open source & signed
Flowsta Vault is MIT-licensed and fully public — read every line. Windows and macOS installers are code-signed, so your OS shows Flowsta as the publisher.
No-account recovery
Your identity is a 24-word BIP39 phrase, not an account. Restore it on any device with no reset email and no recovery process — the same phrase always rebuilds the same keys.