Turn real passwords into private codes that you can safely write down and only you can recover later

Real password

BlueCat42!

Encoded password

NU/*,0BYI7

Same length. Different characters. Recoverable only with your unique matrix and personal directive.

PangolinMatrix turns real passwords into unrecognizable text. Write down the encoded version instead of the real password. Recover it later with your private matrix.

  • No real passwords stored
  • US$19 lifetime account option

Sample encoding matrix

9 x 9
Sample Encoding BlueCat42! Directive: 3R,5D NU/*,0BYI7

3R,5D means move 3 right, then 5 down for each character. To decode, reverse it: 3L,5U.

First letter only

B becomes T then N

3 right, then 5 down

Sample
3R
5D
G
0
q
%
L
8
x
@
R
2
v
,
A
m
:
e
K
!
n
B
_
5
T
z
.
W
c
P
9
d
?
Y
1
h
-
Q
s
M
;
3
f
&
U
a
/
J
k
6
E
o
+
V
r
C
*
p
7
I
=
b
X
t
D
\
4
g
#
N
w
H
F
~
i
$
S
l
Z
u
O
y
j

You do not have to count cells every time. After signup, your matrix page includes an encode/decode helper. See the helper in action.

Prefer to understand first?

Read the security model

See exactly what PangolinMatrix stores, what it never stores, and why separation matters.

Read the security model →

Free browser-only option

Try the No-Account Kit

Generate a browser-only matrix and directive for offline use. You stay fully in control.

Use the No-Account Kit →

How to keep it safe

The protection comes from keeping three pieces separate

1. Matrix

Your matrix stays in PangolinMatrix

Protected by your account password and email code.

You can also print or save a private backup for offline recovery.

2. Encoded passwords

Your encoded passwords stay elsewhere

Keep them in a spreadsheet, notebook, or cloud drive.

Never copy or store your real passwords there.

3. Directive

Your directive stays separate

Memorize it, or save it somewhere different from both the matrix and encoded passwords.

This is the piece you should avoid storing beside the other two.

Walkthrough

See it live in 1 minute

Watch a quick example of encoding a password, writing down only the encoded version, and decoding it back when needed.

Demo only. Never record or share real passwords, your directive, or your full private matrix.

Your real passwords never touch our servers — by design

PangolinMatrix stores your account and private matrix, but not the real passwords you encode!

Read the full security model →

Frequently Asked Questions

Does PangolinMatrix store my real passwords?

No. The helper runs in your browser. PangolinMatrix stores your account and private matrix, but not the real passwords you type into the helper.

What should I keep separate?

Keep your encoded password list away from your matrix. Your directive should be memorized or saved separately, because it is not the main security boundary.

What happens if I lose my matrix?

You may not be able to recover encoded passwords. Print or save a private backup of your matrix and store it somewhere separate from your encoded password list.

Trust, honestly stated

No invented testimonials. No inflated user counts.

PangolinMatrix is new. The security model is public, the tool explains what it stores, and feedback is welcome from people who want to review the idea carefully.

Start with separation

Turn real passwords into private codes that you can safely write down and only you can recover later

Keep a password list that is useless without your private matrix.

Know someone who still writes real passwords down?

Share PangolinMatrix with them after you understand the idea.