Inherit Vault logo Inherit Vault

How We Protect Your Data

How Inherit Vault protects your data

Encrypted on your device, not ours

Everything you put in your vault is encrypted in your browser before it leaves your device, using a key derived from your password. What reaches our servers is ciphertext: a locked box we cannot open. This is not a policy promise, it is how the system is built. We hold no master key, no escrow key, and no backdoor. Nobody at Inherit Vault, no hacker who breaches our servers, and no authority who compels us can read your vault.

The Recovery Certificate, how your family gets in anyway

When you create your vault you receive a printed Recovery Certificate carrying your recovery phrase. We recommend storing it with your will (your solicitor can hold it in the same packet) and keeping a second copy somewhere safe. It is the one key that can open your vault besides your password. If you lose your password AND your certificate, your vault is gone, permanently, mathematically, for everyone. That is the price of genuine privacy, and we ask you to confirm once a year that you still know where your certificate is.

What happens when you die

Your nominated executor submits a death certificate and their own identity documents. After review and a mandatory 14-day waiting period, during which you and your co-executors are notified, so a fraudulent claim can be challenged, we release the still-encrypted vault to your executor. They unlock it with the recovery phrase from your printed certificate. A fraudster with forged documents would receive an unreadable locked box: the paper certificate held with your will is the second, physical key.

Independent of us

You can export your complete (encrypted) vault at any time, and we publish a small, open-source, offline tool at www.inheritvault.com/decrypt.html that can decrypt an export using only your recovery phrase (a QR code on your printed Recovery Certificate points to the same place). Your family's access does not depend on Inherit Vault existing.

Additional protections

Two-factor authentication protects every account: nothing can be stored in a vault until it is switched on, and executor, partner, and admin access always requires it. Repeated failed logins lock accounts progressively, failed attempts are logged and flagged for review, and every security-relevant action is written to an append-only audit log. Backups are encrypted and stored in a separate datacenter from our servers.

Questions? Contact support@inheritvault.com.