What works so far
This is not finished, and I would rather you heard that here than found out later. Below is what is done, what is half-done, and what has not been started.
- the server
- works
- vaults, sharing, files, accounts and devices.
- the command-line tool
- works
- signing in, managing vaults, handing passwords to scripts.
- keys for scripts
- works
- scoped keys and the local helper that answers to them.
- web and desktop app
- being built
- the same core underneath. Not finished.
- phone and browser
- being built
- the groundwork is there, the apps are not.
- forgotten password recovery
- not done
- the recovery kit does not work yet. This one matters.
- signing up
- not open
- nothing is being charged, and you cannot create an account.
- outside security review
- none
- nobody independent has checked the design.
Should you use it yet?
Not for the passwords you cannot afford to lose. Account recovery does not work, so a forgotten master password today means a lost vault. Nobody outside the project has reviewed the design either.
If you want to read the design rather than take my word for it, the protocol and the threat model are written down, including the parts that are still only plans.