End-to-end encryption for your live vault
Contents encrypt on your device before upload. That means your live vault is zero-knowledge: HeirVault stores ciphertext and cannot decrypt it.
Our commitments
Trust is a set of product rules we can explain in plain English.
Contents encrypt on your device before upload. That means your live vault is zero-knowledge: HeirVault stores ciphertext and cannot decrypt it.
Named people get access only after your check-in rules and waiting period allow it. Everyday misses get a real buffer before anything opens.
Your password unlocks encryption in the browser. We receive ciphertext and account facts to run the product, not a key that opens what you left.
Account email, billing, and release timing are visible to us so the product can run. Live vault contents are not. Assisted handoffs store a protected key for that beneficiary only.
Upgrading changes capacity and release controls, not whether your live vault uses end-to-end encryption.
Runs the product
Stays encrypted
The real boundary
Protected by end-to-end encryption, your live vault is zero-knowledge: it encrypts on your device before upload. Account facts run the product. They do not open vault contents.
What stays private
Docs, passwords, and files
Bodies, attachments, and readable content stay encrypted at rest on our servers.
Titles and folder names
When your vault is locked, even names stay encrypted.
Password and vault key
Derived on your device. Recovery stays with your emergency kit, not with us.
What runs the product
A small set of account facts. Each one has a job. None of them decrypt your vault.
Delivery you choose
Your live vault is protected by end-to-end encryption. Each beneficiary gets a separate handoff. You choose who holds that handoff key.
End-to-end encrypted live vault ciphertext, account email, billing, and release timing. For Free system-assisted delivery, a protected key for that beneficiary handoff only.
Your live vault key and cleartext vault password. For owner-shared delivery, the beneficiary password stays with you to share out of band. For direct account delivery, the beneficiary holds the account key.
Named people get a claim link, create or sign in to an account with the invited email, and unlock their handoff in the browser. Assisted delivery transfers a protected handoff key to their account after claim. Invite now uses an enrolled account key. Owner-shared uses a beneficiary password shared out of band.
We do not claim end-to-end encryption for every handoff. Your live vault is end-to-end encrypted. Assisted silent delivery stores a protected handoff key, so that handoff is not end-to-end to the beneficiary alone. Pro and Shield can choose end-to-end handoffs by inviting the beneficiary now or sharing a beneficiary password.
How it is built
Your live vault encrypts on your device first, so it stays zero-knowledge to us. What we store is ciphertext plus the metadata needed to run leave, check-in, waiting period, and claim.
Docs, passwords, files, and sensitive titles are encrypted in the browser before they leave your device.
One password signs you in via OPAQUE and unlocks vault encryption on your device. Servers store an opaque verifier and wrapped keys.
Passkeys and optional authenticator MFA protect the account. Vault contents unlock with your password, or a compatible passkey wrap.
Named people receive only designated content, and only when your check-in and waiting-period rules allow it. On Pro and Shield, a majority of witnesses can start vault release early. Witnesses cannot stop one; only your own check-in does that.
Account security
Vault encryption and account sign-in work together, with different jobs.
Account layer
Passkeys and MFA
Protect or open the account
Sessions and recovery
Sign-in history and emergency kit
Vault layer
End-to-end vault encryption
Password unlocks contents on your device
Account sign-in alone does not open this
Your cleartext password stays on your device. Sign-in and vault unlock share one secret you control.
Use a passkey on trusted devices for faster access. Compatible authenticators can unlock your vault; your password remains the root secret.
Require an authenticator app code after password sign-in. Passkeys can skip this step. Keep backup codes offline.
Save your recovery phrase offline at setup. It is your path back in if you forget the password. Without the password and kit, vault contents stay sealed, including from us.
Review recent sign-ins with device details and approximate location when MaxMind is configured. Free plans do not include session history.
Device or script check-ins can reset your timer without opening the web app. Keys reset timing only; they do not unlock vault contents. Revoke keys you no longer use.
Shield coercion controls
Duress password: a second password for when you are forced to unlock. Shield opens a decoy vault, alerts a trusted contact, and locks primary access. It is for device-level coercion, not a fake identity, and cannot help if the real password was already captured.
A second password for when you are forced to unlock. It opens a decoy vault you prepared. The session looks normal on screen while your real vault stays sealed.
A discreet email reaches your trusted contact, and primary vault access locks for a window you choose. Check-in timing keeps running.
Schedule destruction of the real vault with a delay you choose from 1 to 72 hours. You can cancel from a safe session if it was a false alarm. Panic and kill API keys can trigger the same path from a device.
Release path
Nothing moves while you check in
Check-in
On schedule
Grace buffer
Missed check-in waits
Witnesses
Optional on Pro and Shield
Scoped claim
Only what you designated
Release safety
Family vaults need a reliable way for the right people to claim, and room for everyday missed check-ins.
Check in on your schedule. Many people use the default of every 30 days.
Free uses a 14-day waiting period after a missed check-in. Pro lets you choose 7 to 14 days. Shield lets you choose 1 to 14 days. Every plan sends three warnings by default at 7, 3, and 1 days before your deadline and before the waiting period ends. Pro and Shield can customize those timings. Overdue notices still send when the waiting period starts.
Optional witnesses can confirm whether release should proceed after the waiting period ends. Witnesses do not receive vault contents or delivery keys.
When release begins, each person gets only what you designated for them at the vault, folder, or file level. Nothing more.
How encryption works
Follow the path once. Keys stay local, content is encrypted before upload, and claim waits on your rules.
Readable content exists on your device. What we store is encrypted data plus the metadata needed to run release.
Keys on your device
End-to-end: derived locally, never sent cleartext
Password
Unlocking locallyEnd-to-end encrypted. That means we store ciphertext only.
Open source crypto
The client-side live vault library is public on GitHub as TrueWear/heirvault-crypto and on npm as @heirvault/crypto (Apache-2.0). You can read the algorithms that encrypt in your browser before upload. That means HeirVault stores ciphertext and cannot decrypt your live vault. Assisted delivery stores a protected handoff key for that beneficiary path and is not in this library. The full product is not open source. The library has not been third-party audited yet.
Your part
The product protects what you leave by design. These choices keep that protection lasting for the people you care about.
Who this is for
HeirVault is built first so families can leave what matters and claim calmly. Families store will and policy copies beside practical notes. The same check-in and waiting-period model also fits journalists and others who need contingency handoffs to reach named editors, lawyers, or trusted contacts if they cannot check in. We do not draft wills, and we do not investigate why a check-in was missed.
Family handoff
Docs, logins, and files for beneficiaries
Timed contingency
Editors, counsel, trusted contacts
One release model
Check-in, grace, then scoped claim for named contacts only
One check-in model. We do not investigate why a check-in was missed.
What runs on third-party infrastructure
Transparency
Like most modern products, HeirVault runs on trusted cloud infrastructure for hosting, data storage, email, and billing. Those services help operate the product. Your live vault stays end-to-end encrypted and zero-knowledge, so none of them receive your password or vault encryption keys. For how account and operational data is handled, read the Privacy Policy.