Your password becomes a key
Clavis runs your password through Argon2id — a slow, memory-hard function built to resist brute-force and custom cracking hardware. Clavis measures your PC once and uses as much memory as it comfortably can (up to 128 MiB per file), so each guess costs an attacker more. The result is the key; the password itself is never stored or sent anywhere. While you choose a password, Clavis estimates how long it would take to crack — checking it against the 10,000 most common passwords and patterns like keyboard runs, dates and l33t swaps — and tells you why a weak one is weak.