What we built, and what we won't do.
Vaulant is a place to put things you'd be ruined to lose. The security has to be real, and we have to be able to explain it. Here's the short version, then the long one.
The promise, in plain words
- While you're using it, only you can read what you store.
- For what you leave behind, you choose who holds the key: us, or a custodian you name.
- If something happens to you, only the people you chose receive what you assigned them, and only after a long, loud waiting period.
How it actually works
- Your items are scrambled on your device before they ever reach us.
- The key that unscrambles them is generated on your device and never leaves it.
- Every change to your vault is recorded in a tamper-evident log we keep separate from everything else, so we can prove nothing was altered.
The longer version
Where the encryption happens
On your device, in your browser. When you create a password or upload a document, your device encrypts it before sending it. Our servers receive a sealed envelope they cannot open. Day to day, we could not produce your bank password if a court asked us to: the one exception is the inheritance set at Handoff, under the succession option you choose, and only after the time-locked waiting period, never before. The only way to read your items day to day is from one of your devices, signed in as you.
Who can unlock what you leave behind
Your everyday vault is yours alone: we can't open it. Succession is the one place you make a deliberate choice. The simplest option (the default) lets Vaulant hold the key to your inheritance set, so we can pass it on for you, but only after the waiting period, never before, and never your everyday vault. Prefer that we can't reach even that? Name a custodian (a person you trust, or your own offline backup) and the key is split so no one, us included, can unlock it alone.
How we know it's still you
When you sign in on a new device, you use a one-time code sent to your email, your Google account, or a passkey saved to your device (the same kind that protects your iCloud Keychain). To unlock the vault itself you either touch a device passkey or enter your passphrase: a separate secret we never see, set when you signed up. Sign in with Apple is coming later.
What happens if you forget everything
Your passphrase unlocks your vault on any device, even if you lose every gadget you own, it's set at signup and never touches our servers. For extra durability you can also print a Safety Envelope: 12 plain words on paper that work as a backup to the passphrase. Keep it somewhere safe, and consider telling one successor where it is.
What if we ever wind down
We've published a written commitment: 90 days' notice before any service change, full data export available the entire time, and the decryption tool released openly so you can read your vault forever, with or without us. The full text is on our If we go away page.
Where it runs
Vaulant lives on AWS, in audited, isolated accounts. Production data and audit logs are in different accounts so a compromise of one can't tamper with the other. We run privacy-preserving error monitoring so we can catch bugs: it's scrubbed of contents and never sees what's inside an item. We run no advertising trackers and no cross-site analytics. We use AWS for what AWS is good at, and nothing else.
What we will publish
- An external cryptographic protocol review, before paid public launch.
- A transparency report, listing any government requests and our responses.
- The Recovery Tool that decrypts your data offline, source-available.
- A bug bounty, once we're past closed beta.
Found a vulnerability now, before the bounty program exists? Email security@vaulant.com, we read every report and respond.
Have more questions?
Read the FAQ, or open a vault and see how it works for yourself.