HeirVault
How it worksPricingSecurityAlternativesFAQ
HeirVault

Leave docs, logins, bank details, spreadsheets, will copies, and files for contacts you name. They claim when you can't. End-to-end encrypted. Your live vault encrypts in your browser before upload. That means HeirVault stores ciphertext and cannot decrypt your live vault.

Product

How it worksPricingAlternativesReferralsSign upSign in

Trust

SecurityPassword generatorPassphrasesPassphrase strengthContinuityDuress passphraseHelp

Who it's for

FamiliesCryptoFoundersHigh-riskJournalists

Legal

TermsPrivacyCookies

HeirVault. Leave docs, logins, bank details, and will copies for the contacts you name. They claim when you can't. Your live vault is end-to-end encrypted.

© 2026 TrueWear, LLC. All rights reserved.

Back to Help Center

Security and privacy

End-to-end encryption, passphrases, passkeys, MFA, and recovery.

Your live vault is protected by end-to-end, zero-knowledge encryption. It encrypts in your browser before upload, so HeirVault cannot decrypt it. HeirVault-assisted delivery stores a protected key for that beneficiary handoff only and transfers it after claim. That means assisted handoffs are not end-to-end to the beneficiary alone. Direct-account and owner-shared delivery keep the handoff key off HeirVault servers.

Yes. HeirVault uses one passphrase to sign you in (via OPAQUE, without sending the cleartext) and to unlock vault encryption on your device. Compatible passkeys can also unlock the vault. Email codes sign you into the account only and never unlock the vault. If you lose the passphrase and your emergency kit, those contents cannot be recovered by us.

Prefer a long unique passphrase over a short clever password. HeirVault requires at least 12 characters. Your passphrase stays with you and unlocks the vault on your device. For passwords vs passphrases and end-to-end encryption in plain English, open the Passphrases page from the site footer or Security page. For Argon2id rate anchors and a browser-only lab, open Passphrase strength.

Use your emergency kit and recovery phrase, which you store offline at setup. We cannot reset vault encryption for you. If both the passphrase and recovery phrase are lost, vault contents cannot be recovered.

It includes a recovery phrase created when you set up your vault. Store it offline. It is how you recover vault access if you forget your passphrase. See the emergency kit guide in Help for steps.

Passkeys let you sign in with Face ID, Touch ID, Windows Hello, a hardware security key, or a password manager. On HeirVault, adding a passkey also enrolls vault unlock when the authenticator supports it, so the same passkey can open your account and unwrap your vault key. Your passphrase remains the root secret and recovery path. Email codes and Google sign-in create an account session only and never unlock the vault.

Vault unlock needs a WebAuthn capability called PRF (a per-credential secret from your authenticator). Platform authenticators usually support this: iCloud Keychain on recent macOS and iOS, Google Password Manager, and Windows Hello on recent Windows. Many hardware keys (for example YubiKey) also support it, and some password managers such as 1Password do when PRF is available. Other password managers may store a passkey for sign-in only. If PRF is missing, you can still sign in with that passkey, then unlock with your passphrase (or a prior unlock wrap already saved in that browser). We never receive your passphrase or a clear vault key. Encrypted unlock wraps we store for a passkey are opaque ciphertext we cannot use.

No. Email one-time codes can sign you into the account only. Unlocking encrypted vault contents still requires your passphrase, a PRF-capable passkey with vault unlock enrolled, or your recovery phrase from the emergency kit.

After a period of inactivity (15 minutes by default; change this under Account → Appearance), or when you sign out, key material is cleared from browser memory and any local device unlock wrap on that device. Idle timeout signs you out of the account entirely so the app never stays signed in with a locked vault. Sign in again with your passphrase to continue. A normal page refresh keeps the vault unlocked until idle timeout or sign-out.

On Pro and Shield, you can review recent sign-in sessions with device details and approximate location when geo enrichment is configured. Free plans do not include session history. Session metadata is for account security, not vault plaintext.

Optional authenticator MFA adds a one-time code from an authenticator app after passphrase, email code, or Google sign-in. Passkeys can skip this step. Backup codes recover MFA access if you lose the authenticator. MFA protects account sign-in. It does not unlock vault contents by itself.

Related guides

  • Save your emergency kit

    Store your recovery phrase offline so you can regain vault access if you forget your passphrase.

Back to Help Center