End-to-end encryption for your live vault
Contents encrypt on your device before upload. That means your live vault is zero-knowledge: HeirVault stores ciphertext and cannot decrypt it.
Security
Your live vault is zero-knowledge and encrypts in your browser before upload. That means HeirVault stores ciphertext and cannot decrypt your live vault. Named people claim only when you can't keep checking in.
End-to-end encrypted
Encrypts in your browser
We store ciphertext
Cannot decrypt live vault
Joint checking
Bank account · for Esme
8f3a91c0e2b74d6a1f90c3e8b2d547a1c6e03f9b8d2e4c71a91f90c3e8b2d547a1c6e03f9b8f3a91c0e2b74d6a9c418b2e70b2d547a1c6e03f9b8f3a91c0e2b74d6a1f90c3e851a07c4e29
a1c6e03f9b8f3a91c0e2b74d6a1f90c3e8b2d547c4a19e6b2dc0e2b74d6a1f90c3e8b2d547a1c6e03f9b8f3a917e4d2a60f803f9b8f3a91c0e2b74d6a1f90c3e8b2d547a1c6e0d93c5a18e4
e8b2d547a1c6e03f9b8f3a91c0e2b74d6a1f90c3b7e25d84a0b2d547a1c6e03f9b8f3a91c0e2b74d6a1f90c3e851a07c4e2974d6a1f90c3e8b2d547a1c6e03f9b8f3a91c0e2b7a46f9d2c50
1f90c3e8b2d547a1c6e03f9b8f3a91c0e2b74d6a9c418b2e7003f9b8f3a91c0e2b74d6a1f90c3e8b2d547a1c6e0d93c5a18e48f3a91c0e2b74d6a1f90c3e8b2d547a1c6e03f9b8d2e4c71a9
End-to-end encrypted. That means we store ciphertext only.
Our commitments
Trust is a set of product rules we can explain in plain English.
Contents encrypt on your device before upload. That means your live vault is zero-knowledge: HeirVault stores ciphertext and cannot decrypt it.
Named people get access only after your check-in rules and waiting period allow it. Everyday misses get a real buffer before anything opens.
Your passphrase unlocks encryption in the browser. We receive ciphertext and account facts to run the product, not a key that opens what you left.
Account email, billing, and release timing are visible to us so the product can run. Live vault contents are not. Assisted handoffs store a protected key for that beneficiary only.
Upgrading changes capacity and release controls, not whether your live vault uses end-to-end encryption.
End-to-end encrypted
Encrypts in your browser
We store ciphertext
Cannot decrypt live vault
Joint checking
Bank account · for Esme
8f3a91c0e2b74d6a1f90c3e8b2d547a1c6e03f9b8d2e4c71a91f90c3e8b2d547a1c6e03f9b8f3a91c0e2b74d6a9c418b2e70b2d547a1c6e03f9b8f3a91c0e2b74d6a1f90c3e851a07c4e29
a1c6e03f9b8f3a91c0e2b74d6a1f90c3e8b2d547c4a19e6b2dc0e2b74d6a1f90c3e8b2d547a1c6e03f9b8f3a917e4d2a60f803f9b8f3a91c0e2b74d6a1f90c3e8b2d547a1c6e0d93c5a18e4
e8b2d547a1c6e03f9b8f3a91c0e2b74d6a1f90c3b7e25d84a0b2d547a1c6e03f9b8f3a91c0e2b74d6a1f90c3e851a07c4e2974d6a1f90c3e8b2d547a1c6e03f9b8f3a91c0e2b7a46f9d2c50
1f90c3e8b2d547a1c6e03f9b8f3a91c0e2b74d6a9c418b2e7003f9b8f3a91c0e2b74d6a1f90c3e8b2d547a1c6e0d93c5a18e48f3a91c0e2b74d6a1f90c3e8b2d547a1c6e03f9b8d2e4c71a9
End-to-end encrypted. That means we store ciphertext only.
The real boundary
Protected by end-to-end encryption, your live vault is zero-knowledge: it encrypts on your device before upload. Account facts run the product. They do not open vault contents.
What stays private
Docs, passwords, and files
Bodies, attachments, and readable content stay encrypted at rest on our servers.
Titles and folder names
When your vault is locked, even names stay encrypted.
Passphrase and vault key
Derived on your device. Recovery stays with your emergency kit, not with us.
What runs the product
A small set of account facts. Each one has a job. None of them decrypt your vault.
Delivery you choose
Your live vault is protected by end-to-end encryption. Each beneficiary gets a separate handoff. You choose who holds that handoff key.
End-to-end encrypted live vault ciphertext, account email, billing, and release timing. For Free system-assisted delivery, a protected key for that beneficiary handoff only.
Your live vault key and cleartext vault passphrase. For owner-shared delivery, the beneficiary passphrase stays with you to share out of band. For direct account delivery, the beneficiary holds the account key.
Named people get a claim link, create or sign in to an account with the invited email, and unlock their handoff in the browser. Assisted delivery transfers a protected handoff key to their account after claim. Invite now uses an enrolled account key. Owner-shared uses a beneficiary passphrase shared out of band.
We do not claim end-to-end encryption for every handoff. Your live vault is end-to-end encrypted. Assisted silent delivery stores a protected handoff key, so that handoff is not end-to-end to the beneficiary alone. Pro and Shield can choose end-to-end handoffs by inviting the beneficiary now or sharing a beneficiary passphrase.
How it is built
Your live vault encrypts on your device first, so it stays zero-knowledge to us. What we store is ciphertext plus the metadata needed to run leave, check-in, waiting period, and claim.
Docs, passwords, files, and sensitive titles are encrypted in the browser before they leave your device.
One passphrase signs you in via OPAQUE and unlocks vault encryption on your device. Servers store an opaque verifier and wrapped keys.
Passkeys, optional authenticator MFA, email one-time codes, and Google sign-in help protect or open the account. Vault contents still unlock with your passphrase (or a compatible passkey wrap).
Named people receive only designated content, and only when your check-in and waiting-period rules allow it. On Pro and Shield, a majority of witnesses must approve vault release.
Account security
Vault encryption and account sign-in work together, with different jobs.
Account layer
Passkeys and MFA
Protect or open the account
Sessions and recovery
Sign-in history and emergency kit
Vault layer
End-to-end vault encryption
Passphrase unlocks contents on your device
Account sign-in alone does not open this
Your cleartext passphrase stays on your device. Sign-in and vault unlock share one secret you control.
Use a passkey on trusted devices for faster access. Compatible authenticators can unlock your vault; your passphrase remains the root secret.
Require an authenticator app code after passphrase, email code, or Google sign-in. Passkeys can skip this step. Keep backup codes offline.
Save your recovery phrase offline at setup. It is your path back in if you forget the passphrase. Without the passphrase and kit, vault contents stay sealed, including from us.
Review recent sign-ins with device details and approximate location when MaxMind is configured. Free plans do not include session history.
Device or script check-ins can reset your timer without opening the web app. Keys reset timing only; they do not unlock vault contents. Revoke keys you no longer use.
Shield coercion controls
Duress passphrase: a second passphrase for when you are forced to unlock. Shield opens a decoy vault, alerts a trusted contact, and locks primary access. It is for device-level coercion, not a fake identity, and cannot help if the real passphrase was already captured.
A second passphrase for when you are forced to unlock. It opens a decoy vault you prepared. The session looks normal on screen while your real vault stays sealed.
A discreet email reaches your trusted contact, and primary vault access locks for a window you choose. Check-in timing keeps running.
Schedule irreversible destruction of the real vault with a delay you choose from 1 to 72 hours. Panic and kill API keys can trigger the same path from a device.
Release path
Nothing moves while you check in
Check-in
On schedule
Grace buffer
Missed check-in waits
Witnesses
Optional on Pro and Shield
Scoped claim
Only what you designated
Release safety
Family vaults need a reliable way for the right people to claim, and room for everyday missed check-ins.
Check in on your schedule. Many people use the default of every 30 days.
Free and Pro use a 14-day waiting period after a missed check-in. Shield lets you choose 3 to 14 days. Reminder emails cover pre-due through final countdown; you can opt out in account prefs.
Optional witnesses can confirm whether release should proceed after the waiting period ends. Witnesses do not receive vault contents or delivery keys.
When release begins, each person gets only what you designated for them at the vault, folder, or file level. Nothing more.
How encryption works
Follow the path once. Keys stay local, content is encrypted before upload, and claim waits on your rules.
Readable content exists on your device. What we store is encrypted data plus the metadata needed to run release.
Keys on your device
End-to-end: derived locally, never sent cleartext
Passphrase
Unlocking locallyEnd-to-end encrypted. That means we store ciphertext only.
Your part
The product protects what you leave by design. These choices keep that protection lasting for the people you care about.
Who uses timed release
HeirVault is built first as a dead man's switch for docs, passwords, spreadsheets, will copies, and files you leave. Families store will and policy copies beside practical notes. The same check-in and waiting-period model also fits journalists and others who need contingency handoffs to reach named editors, lawyers, or trusted contacts if they cannot check in. We do not draft wills, and we do not investigate why a check-in was missed.
Family handoff
Docs, logins, and files for beneficiaries
Timed contingency
Editors, counsel, trusted contacts
One release model
Check-in, grace, then scoped claim for named contacts only
One check-in model. We do not investigate why a check-in was missed.
Transparency
Like most modern products, HeirVault runs on trusted cloud infrastructure for hosting, data storage, email, and billing. Those services help operate the product. Your live vault stays end-to-end encrypted and zero-knowledge, so none of them receive your passphrase or vault encryption keys. For how account and operational data is handled, read the Privacy Policy.