Your vault
Your identity and space are secured with a private key that you control.
A Seed vault is a secure container for private keys. It works much like a password manager.
You can export your keys as a backup and use the desktop app in “local vault” mode. This is the default until you connect a remote vault.
Remote vaults
You can use our free vault server or host your own.
Your remote vault is encrypted with a separate secret key: the vault decryption key (VDK). The server stores the encrypted vault and encrypted copies of the VDK.
The VDK is encrypted separately for each device or recovery method: web passkeys, desktop app keys, and a recovery password. You control the keys needed to decrypt these copies. The vault server does not receive those keys, so it cannot read your vault.
Opening and updating your vault
When you log in, you prove you control your device key. The server sends you the encrypted vault and your encrypted copy of the VDK. Your device or browser decrypts the VDK, then uses it to decrypt the vault.
To save changes, your device encrypts the vault and sends it to the server with a signature from your private device key. The server checks the signature to confirm you can update the vault.
Do you like what you are reading? Subscribe to receive updates.
Unsubscribe anytime