Is rotation supported? And if the main password is compromised doesn't that compromise all future derived passwords too?
It also means an attacker needs only the main password and knowledge of which derived system one uses. They don't need a vault file as well.