Product / Unlock and recovery

Convenient unlock, without giving up recovery

Biometrics and hardware keys can stand in for the master password. They only remove friction: the vault key still derives from master password plus secret key, and a 24-word recovery kit stays available.

What it does

Two independent ways back into the vault

Unlock can be delegated to the hardware you already carry. Windows Hello, Touch ID, Face ID, Android biometrics or a FIDO2 key such as YubiKey can satisfy the authentication step, so you do not type a long master password every morning.

Recovery is a separate path entirely. A 24-word BIP-39 recovery phrase can unlock and reset the vault if the master password and the device are both gone, and the emergency kit that carries it is written to a file you control rather than to a vendor.

A password hint exists for the in-between case, stored in plaintext on purpose so it can actually remind you — which is why the product warns you not to put the password itself in it.

What hardware binding does, precisely

The authenticator wraps the vault key

Inside a non-exportable keystore, PBKDF2-SHA256 and AES-GCM wrap the vault key so that unlocking can be authorised by the platform authenticator.

The underlying derivation is unchanged

Vault access always derives from master password plus secret key through Argon2id. Hardware binding is a layer on top, never the foundation.

Losing the authenticator costs convenience only

A lost or replaced authenticator does not affect the vault file, its backups, or any record inside it.

Where all three secrets are chosen

Master password, account secret key and the emergency kit are collected once, at setup, on your own device — there is no server-side account to recover them from.

Security Architecture

Where convenience ends and risk begins

A hint is a hint, not a backup

Hardware unlock means anyone who can authenticate on the device, or who holds your security key, can open the vault — that is the point, and it is why device and key security matter. The password hint is stored in plaintext precisely so it can be read back to you, so it must never contain the password itself. A recovery phrase should be written down and kept offline: anyone who reads it can reset your vault.

TPM 2.0

Windows Hello

The platform authenticator is TPM-backed on Windows, and the wrapping key material does not leave that boundary.

Secure Enclave

macOS

On macOS the platform authenticator output is sealed by the Secure Enclave.

BIP-39

Recovery kit

A 24-word recovery phrase can unlock and reset the vault when the password and the device are both unavailable.

Frequently Asked Questions

About unlocking and recovery

Does enabling hardware unlock weaken the vault?

It changes who can open the vault, not how it is encrypted. The records stay encrypted with the same keys, and access still derives from your master password and secret key.

What happens if I lose my security key?

You fall back to the master password, and if you have lost that too, the recovery kit. The vault itself is unaffected — only the convenience factor is gone.

Where should I keep the recovery kit?

Offline, physically, somewhere you would still find it in several years. It is a master key: whoever reads it can reset your vault.

Related pages

Download Installer