Offline vault recovery
Account recovery restores access to the account; the separate vault recovery key restores access to encrypted backup contents.
- Recovery key
- 256 random bits
- Display
- Shown once during setup
- Server storage
- Encrypted recovery slot only
Account access and data decryption stay separate
Resetting an account password does not silently replace the key that encrypts an existing vault. After account recovery, the client can unlock an envelope vault with the previous vault password, the offline vault recovery key, or a matching remembered-device key.
The app requires the customer to acknowledge saving the recovery key before it commits the new vault envelope. Email links, authenticator values, and one-time account recovery codes do not decrypt backup contents.
Protected local convenience
When Remember me is enabled, the Windows client can retain the session and decrypted master key in Windows Credential Manager. Explicit sign-out removes them; an expired account session preserves the local key so reauthentication can safely reopen the same vault.
Put this feature into a recovery plan
Install SaveState on Windows, protect a representative data set, and test the restore before it is urgent.
Choose a plan