Typical password
Eight to ten characters, maybe a capital and a digit. Fine for everyday sites. Quicker to exhaust when protected material is already in hand.
Passphrases
HeirVault protects your live vault with end-to-end, zero-knowledge encryption. One passphrase signs you in and unlocks what you left in the browser. You keep the secret. We keep the ciphertext.
Passphrase
Vault unlocks here
You read your docs on this device
HeirVault servers
What we store
8f3a · c0e2 · end-to-end
Ciphertext only
End-to-end encrypted
That means we store ciphertext
Passwords vs passphrases
Short passwords are convenient. A passphrase of a few ordinary words is still easy to remember, and much stronger against offline guessing.
Short password
Quicker to tryShort familiar patterns fall earlier in the lists.
Passphrase
Far longerA few ordinary words give you far more strength.
Eight to ten characters, maybe a capital and a digit. Fine for everyday sites. Quicker to exhaust when protected material is already in hand.
Several unrelated words, or one long unique string. Each added word or character multiplies how long offline tries take.
Your passphrase signs you in via OPAQUE and unlocks the vault in the browser. Passkeys and MFA help protect the account. Your passphrase remains the root secret you control.
End-to-end encryption
Your live vault encrypts on your device before upload. That means it is zero-knowledge: HeirVault stores ciphertext and cannot decrypt it. Your passphrase unlocks reading on your side.
End-to-end encrypted
Encrypts in your browser
We store ciphertext
Cannot decrypt live vault
Joint checking
Bank account · for Esme
8f3a91c0e2b74d6a1f90c3e8b2d547a1c6e03f9b8d2e4c71a91f90c3e8b2d547a1c6e03f9b8f3a91c0e2b74d6a9c418b2e70b2d547a1c6e03f9b8f3a91c0e2b74d6a1f90c3e851a07c4e29
a1c6e03f9b8f3a91c0e2b74d6a1f90c3e8b2d547c4a19e6b2dc0e2b74d6a1f90c3e8b2d547a1c6e03f9b8f3a917e4d2a60f803f9b8f3a91c0e2b74d6a1f90c3e8b2d547a1c6e0d93c5a18e4
e8b2d547a1c6e03f9b8f3a91c0e2b74d6a1f90c3b7e25d84a0b2d547a1c6e03f9b8f3a91c0e2b74d6a1f90c3e851a07c4e2974d6a1f90c3e8b2d547a1c6e03f9b8f3a91c0e2b7a46f9d2c50
1f90c3e8b2d547a1c6e03f9b8f3a91c0e2b74d6a9c418b2e7003f9b8f3a91c0e2b74d6a1f90c3e8b2d547a1c6e0d93c5a18e48f3a91c0e2b74d6a1f90c3e8b2d547a1c6e03f9b8d2e4c71a9
End-to-end encrypted. That means we store ciphertext only.
Docs, files, and sensitive titles encrypt in the browser. Servers hold ciphertext and the metadata needed to run check-in, waiting period, and claim.
OPAQUE sign-in keeps your cleartext passphrase off the wire. We store an opaque verifier and wrapped keys. Email codes and Google can reach the account, not vault contents.
Someone with account records would see ciphertext and wraps, not open live-vault contents. Reading still needs your passphrase and slow key stretching. That means HeirVault cannot decrypt your live vault. Assisted handoffs store a protected key for that handoff only and are not end-to-end to the beneficiary alone.
HeirVault stretches your passphrase with Argon2id before wrapping vault keys. Length and uniqueness multiply that cost. The secret you choose and the stretching we apply work together.
Your part of the trust model
HeirVault protects what you leave by design. These choices make that protection last for the people you care about.
Emergency kit
Keep offline
Recovery phrase
1
••••
2
••••
3
••••
4
••••
5
••••
6
••••
Your passphrase
Private. Long. Unique.
Recipient secrets
Share another way