PangolinMatrix

Reversibly encode passwords without storing the real ones.

Visit Website
July 9, 2026 Be one of 3 users to get lifetime access to pangolinmatrix.com

Use promo code INDIE3 after email validation, on payment page to skip the payment and get free access to https://pangolinmatrix.com

Comment

July 9, 2026 I made PangolinMatrix paid for saved accounts, but kept the no-account version free

I changed PangolinMatrix’s model: the No-Account Kit is free, and saved Account Matrix access is a one-time paid option.

The idea is still the same: encode real passwords into text you can write down, while keeping the matrix, encoded list, and directive separate.

I’d love feedback on whether this pricing model feels fair for this kind of tool.

Comment

July 1, 2026 I built a tool to reversibly encode passwords without storing the real ones

Hi everyone,

I just launched PangolinMatrix: https://pangolinmatrix.com

It is a tool for people who want a simple way to protect written-down passwords without storing their real passwords inside a traditional password manager.

The idea is:

- each user gets a private 9x9 character matrix

- the user memorizes a small directive, like 7R, 3D (7 Right, 3 Down)

- they encode their real passwords using the matrix

- they write down only the encoded version

- PangolinMatrix never stores real passwords

  • the only way to get back the real password is to follow the reverse way on the unique matrix : 7L, 3U (7 Left, 3 Up)

So even if someone finds the written encoded password, they still need the private matrix and the memorized directive to recover the original password.

I know password/security tools require trust, so I am especially looking for honest feedback:

1. Do you understand the idea within the first minute?

2. Does the homepage make it clear that real passwords are not stored?

3. Does the browser-based helper make the product easier to use, or does it make you less comfortable?

I would really appreciate any feedback, especially from people who are skeptical of password managers or prefer low-tech backup methods.

21 Comments

  1. 2

    worth being explicit about in your threat model: the directive (7R, 3D) is low-entropy — if someone gets both the matrix and the encoded list, brute-forcing every possible directive is trivial. so the real security boundary is keeping the matrix physically separate from the encoded passwords, not the directive itself. i'd message it that way so users don't treat the directive as "the secret". neat low-tech idea though — like a one-time-pad you can actually memorize.

    1. 1

      Hi Marc, You are absolutely right that the matrix and encoded passwords must be kept separately . I emphasize it especially in the security page: /security but perhaps the homepage needs to express it more explicitly.

      The recommended way is that our users access the matrix in their PangolinMatrix account which is protected by login with your account password and a one-time email code. If they like, they can also print the matrix and store it physically or email it or keep it in somewhere secure. My approach is

      1. access the matrix through PangolinMatrix

      2. store encoded passwords as excel sheet on google drive

      3. memorize the short directive

      Thanks for your contribution.

  2. 1

    Interesting concept! The idea is easy to follow, and I like that it encourages users to avoid writing down their actual passwords. One suggestion would be to include a simple visual example on the homepage showing how the encoding and decoding process works—it could help new visitors understand the system even faster. Wishing you success with the project!

    1. 1

      I have just enhanced the homepage with a better visual explanation.

    2. 1

      Hi sophyyy, I am glad that you have found the idea easy to understand. This is where most of our guest users find it complicated at first glance. I will think though to make the idea auto-explaining visually. Although I have put a sample matrix on homepage,, perhaps some of my guest users do not understand the encoding and decoding process still. Lets see if I come up with a new idea to resolve this issue. Thanks.

  3. 1

    I understood the concept after reading through it , but I think the biggest challenge isn't the implementation - it's trust. People are used to either password managers or pen and paper. You'll probably need a simple visual example on the home page showing how a password gets encoded and decided without exposing the real password. That would have made the idea click much faster for me.

    1. 1

      Hi Aman, just changed the homepage. I think it is too much better now. Thanks for your comment.

  4. 1

    Took me a sec to fully get the matrix + directive idea on first read, might be worth a tiny visual example on the homepage to make it click faster. The "never stores real passwords" framing is smart for the skeptical-of-password-managers crowd though, that's a real audience.

    1. 1

      Hi Lily, just made some modifications on the homepage, can you check it and comment please. Knowing if my users really understand the core idea is crucial . Thanks a lot.

  5. 1

    Hi Ahmet, I ran PangolinMatrix through PagePulse because your post asks the exact right question: whether people understand the no-real-password-storage model quickly enough.

    A few things stood out:
    - Replace the hero H1 'PangolinMatrix' with an outcome headline like 'Write down your passwords anywhere — they're useless without your private matrix' — zero dev effort, high clarity impact
    - Remove the social sharing block from the hero and relocate to post-signup — eliminates 5 competing decision points and increases CTA click focus immediately
    - Add three bullet points of microcopy beneath the primary CTA: '✓ No real passwords stored ✓ No subscription required ✓ Works offline' — addresses top 3 objections at the highest-friction moment

    My main read: the trust story is the product. The page needs to make “I can recover the password, but PangolinMatrix can’t” impossible to miss in the first screen.

    Hope useful — ping me once you’ve made changes and I’ll re-run it

    1. 1

      Hi Assaf, I have just made some modifications as per your recommendations. I found them very useful. Thanks.

      1. 2

        Thanks Ahmet, glad it was useful.
        I re‑ran your lPangolinMatrix through PagePulse These are the new insights:
        - Change 'Read security model' from a ghost button to a plain text link below the primary CTA — this single change will increase clicks on 'Create free matrix' with zero development cost. change it to "'Want to understand the security model first? →'"

        - Add a closing CTA section above the footer repeating the primary headline and 'Create My Free Matrix' button — the page currently ends with no conversion moment

        -Add a CTA button directly below the video: 'Ready to create yours? Create My Free Matrix →'

        if you want to check the updated version yourself, you can run it through PagePulse here: https://pagepulse.page/en. you will get the full audit report.

        1. 1

          I have analyzed my homepage using pagepulse and it really changed how it feels and looks. PagePulse is too smart. thanks again.

          1. 1

            That's great to hear, Ahmet. Glad PagePulse helped you improve the page.

            Nice that you applied the changes. I'd give it a little time now and watch whether more visitors click the primary CTA / security-model link.

            If you keep iterating, PagePulse should be useful for checking each version without waiting for manual feedback.

            Also — your "PagePulse is too smart" line made my day. Would you mind if I quote that as feedback?

            1. 1

              Hi Assaf, I do really think that PagePulse is too smart and helpful. I copied and pasted the recommendations of PagePulse into codex and with the work of both I changed the homepage a lot. Please quote it if you wish so. Thanks .

              1. 1

                Thanks Ahmet, appreciate it.

        2. 1

          Thanks Assaf, very useful again. I have applied all. I will check pagepulse too.

  6. 1

    The interesting tension here is trust vs. usability. Removing stored passwords reduces breach risk, but shifts security entirely into human memory + deterministic encoding. That tradeoff is usually where these systems either gain a niche audience or get rejected depending on how clearly the failure modes are communicated.

    1. 1

      Thanks for your comment. I agree with you on gaining a niche audience. Perhaps this will happen naturally. However, I do think that there are people (like me) who want to get the control of everything. In this case , the important thing is to store the 9x9 matrix and the encoded passwords seperarately. The only thing we should remember is the directive which is something like 4R,5D (4Right, 5Down), which is very easy to remember.

      1. 1

        That's the part I found interesting.

        The bigger question isn't whether people can remember the directive.

        It's what security promise the product is actually asking users to trust.

        I have a thought on that strategic decision that's probably better suited for email than a thread. Happy to share if you're interested.

        1. 1

          Yes, I’d be interested. Thank you.

          I agree that the core question is the security promise, not just whether the directive is easy to remember. After the feedback here, I’m trying to message PangolinMatrix more clearly as a separation-based method: encoded passwords and the matrix should not live in the same place, and the directive is a memorized rule rather than the main security boundary.

          Feel free to email me through the contact page: /contact on PangolinMatrix dot com.

About

I built PangolinMatrix because I wanted a simpler way for people to protect passwords without storing their real passwords inside a password manager or without storing in plain-text format.