Security

Protected by end-to-end encryption. Only the contacts you name can claim.

Not for scare. For dignity. Your live vault encrypts in your browser before upload. That means HeirVault stores ciphertext and cannot decrypt your live vault. Named people claim only when your check-in rules allow it.

Our commitments

How we earn trust

Trust is a set of product rules we can explain in plain English.

End-to-end encryption for your live vault

Contents encrypt on your device before upload. That means your live vault is zero-knowledge: HeirVault stores ciphertext and cannot decrypt it.

Delivery waits on your rules

Named people get access only after your check-in rules and waiting period allow it. Everyday misses get a real buffer before anything opens.

Vault keys stay on your device

Your password unlocks encryption in the browser. We receive ciphertext and account facts to run the product, not a key that opens what you left.

Clear about what we can see

Account email, billing, and release timing are visible to us so the product can run. Live vault contents are not. Assisted handoffs store a protected key for that beneficiary only.

Same end-to-end encryption on Free, Pro, and Shield

Upgrading changes capacity and release controls, not whether your live vault uses end-to-end encryption.

The real boundary

End-to-end for your live vault

Protected by end-to-end encryption, your live vault is zero-knowledge: it encrypts on your device before upload. Account facts run the product. They do not open vault contents.

What stays private

  • Docs, passwords, and files

    Bodies, attachments, and readable content stay encrypted at rest on our servers.

  • Titles and folder names

    When your vault is locked, even names stay encrypted.

  • Password and vault key

    Derived on your device. Recovery stays with your emergency kit, not with us.

What runs the product

A small set of account facts. Each one has a job. None of them decrypt your vault.

Account email
Sign-in codes and account notices. Codes open the account, not the vault.
Session signals
Hashed IP and coarse location on Pro and Shield for sign-in review.
Billing and referrals
Charge your plan and attribute referrals.
Ciphertext and timing
Store encrypted payloads, then run check-ins, waiting periods, and claims.

Delivery you choose

Live vault first. Handoffs second.

Your live vault is protected by end-to-end encryption. Each beneficiary gets a separate handoff. You choose who holds that handoff key.

What we store

End-to-end encrypted live vault ciphertext, account email, billing, and release timing. For Free system-assisted delivery, a protected key for that beneficiary handoff only.

What stays with you

Your live vault key and cleartext vault password. For owner-shared delivery, the beneficiary password stays with you to share out of band. For direct account delivery, the beneficiary holds the account key.

What happens at claim

Named people get a claim link, create or sign in to an account with the invited email, and unlock their handoff in the browser. Assisted delivery transfers a protected handoff key to their account after claim. Invite now uses an enrolled account key. Owner-shared uses a beneficiary password shared out of band.

How this differs

We do not claim end-to-end encryption for every handoff. Your live vault is end-to-end encrypted. Assisted silent delivery stores a protected handoff key, so that handoff is not end-to-end to the beneficiary alone. Pro and Shield can choose end-to-end handoffs by inviting the beneficiary now or sharing a beneficiary password.

How it is built

Protected by end-to-end encryption

Your live vault encrypts on your device first, so it stays zero-knowledge to us. What we store is ciphertext plus the metadata needed to run leave, check-in, waiting period, and claim.

End-to-end before upload

Docs, passwords, files, and sensitive titles are encrypted in the browser before they leave your device.

Cleartext password stays with you

One password signs you in via OPAQUE and unlocks vault encryption on your device. Servers store an opaque verifier and wrapped keys.

Account factors protect the account

Passkeys and optional authenticator MFA protect the account. Vault contents unlock with your password, or a compatible passkey wrap.

Only what you designated

Named people receive only designated content, and only when your check-in and waiting-period rules allow it. On Pro and Shield, a majority of witnesses can start vault release early. Witnesses cannot stop one; only your own check-in does that.

Account security

Layers that protect sign-in

Vault encryption and account sign-in work together, with different jobs.

OPAQUE password sign-in

Your cleartext password stays on your device. Sign-in and vault unlock share one secret you control.

Passkeys for sign-in and unlock

Use a passkey on trusted devices for faster access. Compatible authenticators can unlock your vault; your password remains the root secret.

Optional authenticator MFA

Require an authenticator app code after password sign-in. Passkeys can skip this step. Keep backup codes offline.

Emergency kit on every plan

Save your recovery phrase offline at setup. It is your path back in if you forget the password. Without the password and kit, vault contents stay sealed, including from us.

Session history on Pro and Shield

Review recent sign-ins with device details and approximate location when MaxMind is configured. Free plans do not include session history.

Shield check-in API keys

Device or script check-ins can reset your timer without opening the web app. Keys reset timing only; they do not unlock vault contents. Revoke keys you no longer use.

Shield coercion controls

When someone forces an unlock

Duress password: a second password for when you are forced to unlock. Shield opens a decoy vault, alerts a trusted contact, and locks primary access. It is for device-level coercion, not a fake identity, and cannot help if the real password was already captured.

Duress password

A second password for when you are forced to unlock. It opens a decoy vault you prepared. The session looks normal on screen while your real vault stays sealed.

Silent alert and lockdown

A discreet email reaches your trusted contact, and primary vault access locks for a window you choose. Check-in timing keeps running.

Hard kill with a cancellable delay

Schedule destruction of the real vault with a delay you choose from 1 to 72 hours. You can cancel from a safe session if it was a false alarm. Panic and kill API keys can trigger the same path from a device.

Release safety

A clear path, with a real buffer

Family vaults need a reliable way for the right people to claim, and room for everyday missed check-ins.

Check-ins

Check in on your schedule. Many people use the default of every 30 days.

Waiting period before release

Free uses a 14-day waiting period after a missed check-in. Pro lets you choose 7 to 14 days. Shield lets you choose 1 to 14 days. Every plan sends three warnings by default at 7, 3, and 1 days before your deadline and before the waiting period ends. Pro and Shield can customize those timings. Overdue notices still send when the waiting period starts.

Witnesses on Pro and Shield

Optional witnesses can confirm whether release should proceed after the waiting period ends. Witnesses do not receive vault contents or delivery keys.

Least privilege release

When release begins, each person gets only what you designated for them at the vault, folder, or file level. Nothing more.

Continuity

Release keeps running with your check-in path

Once your check-in path is set, we keep running the timing that protects your beneficiaries. Read the full continuity commitment for shutdown and export details.

How encryption works

A short path from your device to encrypted storage

Follow the path once. Keys stay local, content is encrypted before upload, and claim waits on your rules.

Readable content exists on your device. What we store is encrypted data plus the metadata needed to run release.

Open source crypto

Our live vault cryptography is open source.

The client-side live vault library is public on GitHub as TrueWear/heirvault-crypto and on npm as @heirvault/crypto (Apache-2.0). You can read the algorithms that encrypt in your browser before upload. That means HeirVault stores ciphertext and cannot decrypt your live vault. Assisted delivery stores a protected handoff key for that beneficiary path and is not in this library. The full product is not open source. The library has not been third-party audited yet.

Passwords

Go deeper on the secret you control

Passwords vs passwords and end-to-end encryption in plain English. Then open Password strength for rate anchors and a browser-only lab.

Your part

A few habits keep the model strong

The product protects what you leave by design. These choices keep that protection lasting for the people you care about.

  • Choose a long unique password and keep it private.
  • Save your emergency kit offline at setup so you can recover on a new device.
  • Safeguard MFA backup codes if you enable authenticator MFA.
  • Choose delivery per contact under Contacts: HeirVault-assisted silent delivery, invite now, or owner-shared beneficiary password.
  • Keep check-ins current when you travel, set Away until for a bounded pause, or rely on the waiting period before release can begin.
  • Treat Shield API keys like a check-in link, and revoke ones you no longer use.

Who this is for

Family handoff, and people who need a calm contingency path

HeirVault is built first so families can leave what matters and claim calmly. Families store will and policy copies beside practical notes. The same check-in and waiting-period model also fits journalists and others who need contingency handoffs to reach named editors, lawyers, or trusted contacts if they cannot check in. We do not draft wills, and we do not investigate why a check-in was missed.

What runs on third-party infrastructure

  • HostingServes the app
  • StorageHolds ciphertext
  • EmailSends notices
  • BillingHandles payment

Transparency

Infrastructure without the fog

Like most modern products, HeirVault runs on trusted cloud infrastructure for hosting, data storage, email, and billing. Those services help operate the product. Your live vault stays end-to-end encrypted and zero-knowledge, so none of them receive your password or vault encryption keys. For how account and operational data is handled, read the Privacy Policy.

Accountability

Found a security issue?

Email security@heirvault.io. We take responsible reports seriously and will respond as quickly as we can.

Ready when you are

Start on Free with the same leave-and-claim path as Pro and Shield. What you leave is protected by end-to-end encryption until your rules say otherwise.