Kanlane
ENES

For freelancers and agencies

A password manager for your clients’ credentials

Freelancers and agencies collect logins for every client: the website admin, the hosting, the mailbox, the remote desktop. Kanlane keeps them on each client, next to the work, with the password and notes encrypted in your browser.

Updated:

In short

Kanlane is a task and client manager with a built-in password vault, so freelancers and agencies can store each client’s credentials (email, website, server, RDP or VPN) in the same place as that client’s work. Each credential’s password and notes are encrypted in your browser with AES-256 and a master password that Kanlane never stores or receives; the rest of the entry, such as client, username or website, is stored unencrypted. It does not autofill and cannot be shared with a team: it keeps client logins at hand rather than replacing a full password manager.

Where client credentials usually end up

A spreadsheet tab, an email thread, a note on your phone. When a client asks for a change on their site, you lose minutes finding the login. In Kanlane every credential belongs to a client, so it sits next to the task you are working on.

Five credential types

Email / Website, Username / Website, Server, RDP (with port and domain) and VPN, each with its own fields.

Organized by client

Filter by client or type. Each client card counts its passwords and takes you straight to them.

Linked to tasks

Attach a credential to the task that needs it, so the login is there when you start.

Show, copy, hide

Passwords stay hidden. They are only decrypted when you click Show, Copy or Edit.

Quick search

With the vault unlocked, Ctrl K finds credentials by title, username or client, never by the password.

Undo and backups

Deleted a credential by mistake? Undo it. The project backup exports credentials still encrypted.

What a stored credential looks like

An example with made-up data, showing what is encrypted and what is not, as it would appear in the database.

N
North Studio · Website adminEmail / Website
Email · not encryptedweb@northstudio.example
Website · not encryptednorthstudio.example/admin
Password · encrypted••••••••
Notes · encrypted••••••••

How the encryption works

  1. You choose a master password. One per project, at least 8 characters. It is never stored or sent anywhere: it is only used in your browser.
  2. Your browser creates a random 256-bit key. That key encrypts your credentials and is stored wrapped twice: with a key derived from your master password (PBKDF2-SHA256, 300,000 iterations and a random salt) and with your recovery key.
  3. Everything is encrypted before it leaves. Each password and its notes are encrypted with 256-bit AES-GCM and a fresh random IV, using the browser’s own Web Crypto API.
  4. You unlock to read them. The browser derives the key again and decrypts in the tab. The key only lives in memory: after clicking Lock, switching projects or reloading the page, you type the master password again.

What it protects

  • Anyone who gets hold of the database only sees ciphertext for passwords and notes.
  • Kanlane cannot read or recover your passwords: it never has your master password or your recovery key.
  • Plugins have no access to passwords.

What it does not protect

  • The rest of the entry (client, name, email or username, website, IP, port and domain) is stored unencrypted.
  • There is no auto-lock on inactivity: while the vault is unlocked, anyone using your computer can see it.
  • Whatever you copy stays on the clipboard until you copy something else.
  • A weak master password is easier to guess if someone obtains the encrypted data.
  • If you lose both the master password and the recovery key, the passwords cannot be recovered.

The recovery key

When you create the master password, Kanlane gives you a 256-bit recovery key written in groups of four characters (XXXX-XXXX-…). You can copy it or download it as a text file, and you must confirm you saved it before continuing. If you forget the master password, the recovery key lets you set a new one; at that point a new recovery key is generated and the old one stops working.

Comparison: where to keep client credentials

A comparison by type of tool, not by product. The third-party columns describe what is typical for each category; check the actual features of the one you use.

CriterionKanlaneDedicated password manager (such as Bitwarden or 1Password)SpreadsheetNotes app
Password encrypted with a master passwordYes, in the browser (password and notes)Its core purposeOnly if you protect the fileOnly if the app supports it
Other credential fields (username, website)Not encryptedDepends on the productSame as the fileSame as the note
Next to the client, their tasks and contactsYesNo: tasks live in another toolBy handBy hand
Autofill and browser extensionNoCommonNoNo
Sharing credentials with a teamNoCommon on team plansYou share the whole fileYou share the whole note
Regaining access if you forget the master passwordWith your recovery keyDepends on the productNot applicableNot applicable

If you already use a dedicated password manager, Kanlane does not replace it: it can keep each client’s logins next to that client’s work.

Kanlane is not for you if…

  • You need passwords to fill in automatically on websites, or a browser extension.
  • You have to share logins with teammates or with the client: team projects have no vault.
  • You want every field encrypted: only the password and the notes are.
  • You need a password generator or two-factor codes: Kanlane has neither.
  • You want to bring passwords over from another manager or a CSV file: there is no import.
  • You need auto-lock on inactivity or automatic clipboard clearing.

Frequently asked questions

Is Kanlane a good password manager for freelancers who handle client logins?

It is a good fit if you want each client’s credentials next to their tasks and contacts, with the password and notes encrypted in your browser. It does not autofill, has no browser extension and cannot share credentials with a team, so it does not replace a full password manager.

Can Kanlane see my clients’ passwords?

No. Each credential’s password and notes are encrypted in your browser before they are saved, with a key that only your master password or your recovery key can unlock. The rest of the entry is stored unencrypted: client, name, email or username, website, IP, port and domain.

What happens if I forget my master password?

You can set a new one with the recovery key created along with it. Using it generates a new recovery key and the old one stops working. If you lose both the master password and the recovery key, nobody can decrypt those passwords, Kanlane included.

Can I share client credentials with my team or with the client?

No. The vault is personal: team projects have no passwords section, and turning a project into a team project does not copy its passwords. To share a login you need another secure channel.

Does it autofill passwords or have a browser extension?

No. You open the credential, click Copy and paste it where you need it. Kanlane does not clear the clipboard afterwards, so copy something else when you are done.

Can I import passwords from another password manager?

No. There is no import from other password managers or from CSV files. You can export the project backup as a JSON file, which includes the credentials with the password and notes still encrypted.

Try it with your clients

The demo shows the board with sample data and needs no account. The password vault lives inside the app: create your account, open Passwords and choose your master password.