Your server never sees a password
Entries are encrypted before they are sent — in the desktop client, in the browser extension and in the web interface alike. The key is derived from a master passphrase that never reaches the server. Each entry is stored as one block of bytes and a revision number: there is no column for a name, a folder or an address. An administrator with full database access reads the same blocks as someone with a stolen copy.