Security

Protected by end-to-end encryption. Only the contacts you name can claim.

Your live vault is zero-knowledge and encrypts in your browser before upload. That means HeirVault stores ciphertext and cannot decrypt your live vault. Named people claim only when you can't keep checking in.

End-to-end encrypted

Encrypts in your browser

We store ciphertext

Cannot decrypt live vault

vault · end-to-end encrypted

Joint checking

Bank account · for Esme

E2E

8f3a91c0e2b74d6a1f90c3e8b2d547a1c6e03f9b8d2e4c71a91f90c3e8b2d547a1c6e03f9b8f3a91c0e2b74d6a9c418b2e70b2d547a1c6e03f9b8f3a91c0e2b74d6a1f90c3e851a07c4e29

a1c6e03f9b8f3a91c0e2b74d6a1f90c3e8b2d547c4a19e6b2dc0e2b74d6a1f90c3e8b2d547a1c6e03f9b8f3a917e4d2a60f803f9b8f3a91c0e2b74d6a1f90c3e8b2d547a1c6e0d93c5a18e4

e8b2d547a1c6e03f9b8f3a91c0e2b74d6a1f90c3b7e25d84a0b2d547a1c6e03f9b8f3a91c0e2b74d6a1f90c3e851a07c4e2974d6a1f90c3e8b2d547a1c6e03f9b8f3a91c0e2b7a46f9d2c50

1f90c3e8b2d547a1c6e03f9b8f3a91c0e2b74d6a9c418b2e7003f9b8f3a91c0e2b74d6a1f90c3e8b2d547a1c6e0d93c5a18e48f3a91c0e2b74d6a1f90c3e8b2d547a1c6e03f9b8d2e4c71a9

Ciphertext only

End-to-end encrypted. That means we store ciphertext only.

Our commitments

Promises we make, and keep

Trust is a set of product rules we can explain in plain English.

End-to-end encryption for your live vault

Contents encrypt on your device before upload. That means your live vault is zero-knowledge: HeirVault stores ciphertext and cannot decrypt it.

Delivery waits on your rules

Named people get access only after your check-in rules and waiting period allow it. Everyday misses get a real buffer before anything opens.

Vault keys stay on your device

Your passphrase unlocks encryption in the browser. We receive ciphertext and account facts to run the product, not a key that opens what you left.

Clear about what we can see

Account email, billing, and release timing are visible to us so the product can run. Live vault contents are not. Assisted handoffs store a protected key for that beneficiary only.

Same end-to-end encryption on Free, Pro, and Shield

Upgrading changes capacity and release controls, not whether your live vault uses end-to-end encryption.

End-to-end encrypted

Encrypts in your browser

We store ciphertext

Cannot decrypt live vault

vault · end-to-end encrypted

Joint checking

Bank account · for Esme

E2E

8f3a91c0e2b74d6a1f90c3e8b2d547a1c6e03f9b8d2e4c71a91f90c3e8b2d547a1c6e03f9b8f3a91c0e2b74d6a9c418b2e70b2d547a1c6e03f9b8f3a91c0e2b74d6a1f90c3e851a07c4e29

a1c6e03f9b8f3a91c0e2b74d6a1f90c3e8b2d547c4a19e6b2dc0e2b74d6a1f90c3e8b2d547a1c6e03f9b8f3a917e4d2a60f803f9b8f3a91c0e2b74d6a1f90c3e8b2d547a1c6e0d93c5a18e4

e8b2d547a1c6e03f9b8f3a91c0e2b74d6a1f90c3b7e25d84a0b2d547a1c6e03f9b8f3a91c0e2b74d6a1f90c3e851a07c4e2974d6a1f90c3e8b2d547a1c6e03f9b8f3a91c0e2b7a46f9d2c50

1f90c3e8b2d547a1c6e03f9b8f3a91c0e2b74d6a9c418b2e7003f9b8f3a91c0e2b74d6a1f90c3e8b2d547a1c6e0d93c5a18e48f3a91c0e2b74d6a1f90c3e8b2d547a1c6e03f9b8d2e4c71a9

Ciphertext only

End-to-end encrypted. That means we store ciphertext only.

The real boundary

End-to-end for your live vault

Protected by end-to-end encryption, your live vault is zero-knowledge: it encrypts on your device before upload. Account facts run the product. They do not open vault contents.

What stays private

  • Docs, passwords, and files

    Bodies, attachments, and readable content stay encrypted at rest on our servers.

  • Titles and folder names

    When your vault is locked, even names stay encrypted.

  • Passphrase and vault key

    Derived on your device. Recovery stays with your emergency kit, not with us.

What runs the product

A small set of account facts. Each one has a job. None of them decrypt your vault.

Account email
Sign-in codes and account notices. Codes open the account, not the vault.
Session signals
Hashed IP and coarse location on Pro and Shield for sign-in review.
Billing and referrals
Charge your plan and attribute referrals.
Ciphertext and timing
Store encrypted payloads, then run check-ins, waiting periods, and claims.

Delivery you choose

Live vault first. Handoffs second.

Your live vault is protected by end-to-end encryption. Each beneficiary gets a separate handoff. You choose who holds that handoff key.

What we store

End-to-end encrypted live vault ciphertext, account email, billing, and release timing. For Free system-assisted delivery, a protected key for that beneficiary handoff only.

What stays with you

Your live vault key and cleartext vault passphrase. For owner-shared delivery, the beneficiary passphrase stays with you to share out of band. For direct account delivery, the beneficiary holds the account key.

What happens at claim

Named people get a claim link, create or sign in to an account with the invited email, and unlock their handoff in the browser. Assisted delivery transfers a protected handoff key to their account after claim. Invite now uses an enrolled account key. Owner-shared uses a beneficiary passphrase shared out of band.

How this differs

We do not claim end-to-end encryption for every handoff. Your live vault is end-to-end encrypted. Assisted silent delivery stores a protected handoff key, so that handoff is not end-to-end to the beneficiary alone. Pro and Shield can choose end-to-end handoffs by inviting the beneficiary now or sharing a beneficiary passphrase.

How it is built

Protected by end-to-end encryption

Your live vault encrypts on your device first, so it stays zero-knowledge to us. What we store is ciphertext plus the metadata needed to run leave, check-in, waiting period, and claim.

End-to-end before upload

Docs, passwords, files, and sensitive titles are encrypted in the browser before they leave your device.

Cleartext passphrase stays with you

One passphrase signs you in via OPAQUE and unlocks vault encryption on your device. Servers store an opaque verifier and wrapped keys.

Account factors protect the account

Passkeys, optional authenticator MFA, email one-time codes, and Google sign-in help protect or open the account. Vault contents still unlock with your passphrase (or a compatible passkey wrap).

Only what you designated

Named people receive only designated content, and only when your check-in and waiting-period rules allow it. On Pro and Shield, a majority of witnesses must approve vault release.

Account security

Layers that protect sign-in

Vault encryption and account sign-in work together, with different jobs.

Account layer

Passkeys and MFA

Protect or open the account

Sessions and recovery

Sign-in history and emergency kit

Vault layer

End-to-end vault encryption

Passphrase unlocks contents on your device

Account sign-in alone does not open this

OPAQUE passphrase sign-in

Your cleartext passphrase stays on your device. Sign-in and vault unlock share one secret you control.

Passkeys for sign-in and unlock

Use a passkey on trusted devices for faster access. Compatible authenticators can unlock your vault; your passphrase remains the root secret.

Optional authenticator MFA

Require an authenticator app code after passphrase, email code, or Google sign-in. Passkeys can skip this step. Keep backup codes offline.

Emergency kit on every plan

Save your recovery phrase offline at setup. It is your path back in if you forget the passphrase. Without the passphrase and kit, vault contents stay sealed, including from us.

Session history on Pro and Shield

Review recent sign-ins with device details and approximate location when MaxMind is configured. Free plans do not include session history.

Shield check-in API keys

Device or script check-ins can reset your timer without opening the web app. Keys reset timing only; they do not unlock vault contents. Revoke keys you no longer use.

Shield coercion controls

Forced unlock, lockdown, and hard kill

Duress passphrase: a second passphrase for when you are forced to unlock. Shield opens a decoy vault, alerts a trusted contact, and locks primary access. It is for device-level coercion, not a fake identity, and cannot help if the real passphrase was already captured.

Duress passphrase

A second passphrase for when you are forced to unlock. It opens a decoy vault you prepared. The session looks normal on screen while your real vault stays sealed.

Silent alert and lockdown

A discreet email reaches your trusted contact, and primary vault access locks for a window you choose. Check-in timing keeps running.

Hard kill with a cancellable delay

Schedule irreversible destruction of the real vault with a delay you choose from 1 to 72 hours. Panic and kill API keys can trigger the same path from a device.

Release path

Nothing moves while you check in

  1. Check-in

    On schedule

  2. Grace buffer

    Missed check-in waits

  3. Witnesses

    Optional on Pro and Shield

  4. Scoped claim

    Only what you designated

Release safety

A clear path, with a real buffer

Family vaults need a reliable way for the right people to claim, and room for everyday missed check-ins.

Check-ins

Check in on your schedule. Many people use the default of every 30 days.

Waiting period before release

Free and Pro use a 14-day waiting period after a missed check-in. Shield lets you choose 3 to 14 days. Reminder emails cover pre-due through final countdown; you can opt out in account prefs.

Witnesses on Pro and Shield

Optional witnesses can confirm whether release should proceed after the waiting period ends. Witnesses do not receive vault contents or delivery keys.

Least privilege release

When release begins, each person gets only what you designated for them at the vault, folder, or file level. Nothing more.

Continuity

Release keeps running with your check-in path

Once your check-in path is set, we keep running the timing that protects your beneficiaries. Read the full continuity commitment for shutdown and export details.

How encryption works

A short path from your device to encrypted storage

Follow the path once. Keys stay local, content is encrypted before upload, and claim waits on your rules.

Readable content exists on your device. What we store is encrypted data plus the metadata needed to run release.

Keys on your device

Keys on your device

End-to-end: derived locally, never sent cleartext

Passphrase

Unlocking locally
Deriving vault keyArgon2id
What we would store

End-to-end encrypted. That means we store ciphertext only.

Passphrases

Go deeper on the secret you control

Passwords vs passphrases and end-to-end encryption in plain English. Then open Passphrase strength for rate anchors and a browser-only lab.

Your part

A few habits keep the model strong

The product protects what you leave by design. These choices keep that protection lasting for the people you care about.

  • Choose a long unique passphrase and keep it private.
  • Save your emergency kit offline at setup so you can recover on a new device.
  • Safeguard MFA backup codes if you enable authenticator MFA.
  • Choose delivery per contact under Contacts: HeirVault-assisted silent delivery, invite now, or owner-shared beneficiary passphrase.
  • Keep check-ins current when you travel, set Away until for a bounded pause, or rely on the waiting period before release can begin.
  • Treat Shield API keys like a check-in link, and revoke ones you no longer use.

Who uses timed release

Family handoff, and people who need a timed contingency path

HeirVault is built first as a dead man's switch for docs, passwords, spreadsheets, will copies, and files you leave. Families store will and policy copies beside practical notes. The same check-in and waiting-period model also fits journalists and others who need contingency handoffs to reach named editors, lawyers, or trusted contacts if they cannot check in. We do not draft wills, and we do not investigate why a check-in was missed.

Family handoff

Docs, logins, and files for beneficiaries

Timed contingency

Editors, counsel, trusted contacts

One release model

Check-in, grace, then scoped claim for named contacts only

One check-in model. We do not investigate why a check-in was missed.

Transparency

Infrastructure without the fog

Like most modern products, HeirVault runs on trusted cloud infrastructure for hosting, data storage, email, and billing. Those services help operate the product. Your live vault stays end-to-end encrypted and zero-knowledge, so none of them receive your passphrase or vault encryption keys. For how account and operational data is handled, read the Privacy Policy.

Accountability

Found a security issue?

Email security@heirvault.io. We take responsible reports seriously and will respond as quickly as we can.

Ready to leave the path?

Start on Free with the same leave-and-claim path as Pro and Shield. What you leave is protected by end-to-end encryption until your rules say otherwise.