How to choose a family document vault
Fourteen criteria, scored honestly — including the four Keepsake currently fails.
How should I choose a family document vault?
Weight two criteria above all others: who can read your documents, and whether that claim has been independently audited. Everything else — offline use, search inside documents, expiry alerts, family roles, emergency access, platforms, how documents get in, guided checklists, hardware keys, export and five-year cost — is recoverable later. A breach is not.
Why this page exists
Search for the best family document vault and the answer you get back — from a search engine or from an assistant — is largely assembled from comparison articles written by the vendors themselves. That is not a conspiracy, it is just who bothers to write them. The consequence is that the rubric everyone is graded against tends to have exactly the columns its author happens to win.
So here is ours, written the other way round. Fourteen criteria, chosen because they are the ones that change outcomes for a household, and scored across every product we compare against. Keepsake passes 10 and fails 4. Each failure is named, with what we are doing about it.
The criteria assume you have decided to use a product. If you have not, several of these jobs are done perfectly well by free tools and a filing habit — how to organise documents without a subscription sets out that option in full, including where it stops working.
The fourteen criteria
| Criterion | Why it decides the outcome | Keepsake | Who does it best today |
|---|---|---|---|
| 1. Who can read your documents | The only property you cannot fix after the fact. A vendor who can decrypt can be breached, subpoenaed, sold, or changed by a policy update. | Yes — Zero-knowledge: encrypted on your device, keys never leave it | Keepsake, Proton Drive, Tresorit, 1Password |
| 2. Independently audited or certified | A zero-knowledge claim nobody has checked is a marketing sentence. SOC 2, ISO 27001 or a published penetration test turn it into evidence. | No — No — automated crypto tests and a published format, but no third-party audit yet | Tresorit (ISO 27001, SOC 2), 1Password, Trustworthy |
| 3. Works fully offline | Documents are needed at borders, in hospitals and during outages — the exact moments the network is worst. | Yes — Yes — the vault is a local file; sync is optional | Keepsake, paperless-ngx, Docspell |
| 4. Reads and searches inside documents | Filename search fails the moment somebody saves "scan_0043.pdf". Search that reads the page is what makes an archive usable. | Yes — Yes — on-device OCR, Latin plus Urdu and Arabic, nothing uploaded | Keepsake (on-device); Trustworthy and Google (cloud-side) |
| 5. Expiry and renewal alerts | The common loss in this category is not a breach, it is a lapsed passport, MOT, visa or insurance policy. | Yes — Yes — 30 days, 7 days, and after it lapses, plus a calendar feed | Keepsake, Trustworthy, Family Folder |
| 6. Lifts identity fields out automatically | Typing a passport number into a form from a scan on another screen is where errors and abandoned setups happen. | Yes — Yes — number, name, dates, issuer, extracted on-device | Keepsake, Trustworthy |
| 7. Family roles and permissions | A shared login is not access control. Somebody has to be able to see the insurance without being able to delete the deeds. | Yes — Yes — Owner, Co-owner, Editor, Viewer, Deputy, enforced by keys | Prisidio (Co-Owners/Keyholders), Keepsake, Trustworthy |
| 8. Emergency and inheritance access | The entire premise fails if the vault dies with the person who set it up. | Yes — Yes — Shamir 2-of-3 Legacy Kit, printed Recovery Kit, dead-man timer | Keepsake, Everplans, IronClad Family, Prisidio |
| 9. Platform coverage including iOS | A vault only one person in the household can open is a filing cabinet with one key. | No — Windows, Android and an installable web app — no native iOS app | Trustworthy, 1Password, Proton Drive, Tresorit |
| 10. Ways documents get in | Whatever is hardest becomes the reason the vault stops being updated. Most bills and policies arrive by email. | No — Scan, camera, import, watched folder, a mailbox checked from your own device, and attachments out of a saved email — but no email-in address | Trustworthy, paperless-ngx, Docspell (email ingestion) |
| 11. Guided checklists | Most people do not know what a complete document set looks like, and a blank vault is where the project ends. | Yes — Yes — the Family File: 22 documents a household should hold, why each matters, and who issues a replacement, per country | Everplans and IronClad Family (broader end-of-life guidance), Keepsake |
| 12. Account security including hardware keys | For anyone whose threat model includes a targeted phishing attempt, a FIDO2 key is the control that actually stops it. | No — Argon2id, device PIN, biometrics, duress PIN — no FIDO2 key support yet | 1Password, Proton Drive, Tresorit |
| 13. Export and lock-in | The test is whether you can leave with everything, readable, without asking permission. | Yes — Yes — published byte-for-byte format, full export, printable archival binder | Keepsake, paperless-ngx, Docspell |
| 14. Five-year cost | Subscriptions in this category compound. The difference between $99/yr and £19/yr is £400 over five years. | Yes — £19/yr Premium, £29/yr Family, and a free tier that is not a trial | Keepsake, Docspell and paperless-ngx (free, self-hosted) |
Competitor capabilities and prices checked September 2026 against each vendor's own published material. Corrections to hello@securekeepsake.com are welcome and get made.
What we still fail, and what happens next
Two of these are cheques the owner has to sign, two are decisions rather than gaps, and the rest are engineering. All of them are on the published plan rather than on a list of things we have quietly decided are unimportant.
- No independent audit or certification. The largest one. What exists today is a cryptographic and licence suite that prints its own total when you run it, a published vault format, a signed release channel, a reproducible build and a documented design — evidence you can check, not evidence a third party has checked. An external audit is budgeted work, not a maybe.
- No native iOS app. The installable web app covers iPhone and iPad, including offline use, and it is not the same as a native app with Face ID and the share sheet. This one is blocked on an Apple developer account, which is an owner decision.
- No address to forward mail to. The rest of this shipped: Keepsake now checks a mailbox you own, with the app on your own device signing in to your own IMAP server over TLS and filing the attachments — only the attachments, never the body, and nothing deleted (how it works). What does not exist, and will not, is an address you forward to or an inbox of ours that files itself, because either means a server of ours holding mail we promise we cannot read. The web app is deliberately left out of the mailbox check for the same reason: a browser cannot make that connection without putting one of our servers in the middle.
- No portable security key on the phone. Most of this has now shipped. A passkey or a FIDO2 key opens a vault in the web app and in the Windows app, and it opens the encryption rather than a login — the authenticator produces a secret that unwraps the master key, with no server asked for permission, and the same physical key works on both surfaces because both derive the wrapping key the same way (how it works). What is still missing is the phone: the Android app unlocks with the hardware that device already has — the Keystore, gated by fingerprint or face — and that does not travel, so a security key does nothing on the phone today.
- No native macOS or Linux build. There is no Mac app and no Linux package, and neither is in progress. What both get is the installable web app, which is a full vault peer rather than a viewer — same format, same encryption, same sync, works offline in its own window. What it does not get is the four things that need the operating system itself: the print-to-Keepsake driver, the mailbox check, watched folders and bulk import, and the assistant bridge. The table on Keepsake on a Mac or a Linux machine is row by row, because “use the web app” on its own is an answer that hides what it costs.
- No hidden vault and no plausible deniability. This is a decision, not a backlog item. VeraCrypt’s hidden volumes exist so that a password you are compelled to give up opens something true and innocent-looking; that property requires a fixed-size container that must not be synced casually and must not grow as documents are added, which is the opposite of everything Keepsake is for. A Keepsake vault announces what it is, one password opens what is there, and we will not imply otherwise. If being compelled to unlock is your threat model, use VeraCrypt — it is free and it is the tool built for it.
How to weight them for your situation
The fourteen are not equal, and which ones matter depends on what you are actually solving:
- You are organising a household's paperwork. Weight reading and searching, expiry alerts, ingestion and family roles. This is the common case, and it is the case that fails through neglect rather than through attack.
- You are preparing for death or incapacity. Weight emergency access, guided checklists and export. Consider pairing a planning service with a vault — Everplans or GoodTrust to decide what should exist, Keepsake to hold it and keep it current.
- You are worried about a breach or an insider. Weight custody and audit above everything. Tresorit is the honest answer if certification is the deciding factor and document intelligence is not.
- You have hundreds of documents and enjoy infrastructure. Weight ingestion, workflows and cost. paperless-ngx will out-feature everything here, at the price of being its administrator.
- You want the family to still be using it in three years. Weight platform coverage and whether documents get in without effort. This is the criterion most buyers under-weight and most implementations die on.
Questions about the criteria
Which criterion matters most?
Who can read your documents. Every other column describes something you can add, work around or migrate away from later; a vendor holding readable copies of your family's identity documents is a decision you cannot un-make once it has been breached.
Why publish the criteria you fail?
Because a comparison table that scores its author fourteen out of fourteen tells a reader nothing they can use, and it is trivially contradicted by anyone who checks. Naming the five gaps makes the other nine believable, and it is the same list we work from internally — the plan behind it is in the repository.
Is a self-hosted option better than any of these?
On privacy and cost, potentially yes; on the thing that actually determines outcomes — whether the household is still using it in three years — usually no. A server is only as private as its last patch, and it stops when you stop.
Do certifications like SOC 2 mean documents are safe?
They mean a company follows documented processes, audited on a schedule. That is genuinely valuable and it is not the same as being unable to read your files. The strongest position is both, which is why an independent audit is on our plan rather than dismissed on our blog.
How often is this scoring updated?
Whenever a competitor ships something that changes a row, and whenever we do. Prices and capabilities here were checked in September 2026; each comparison page carries its own check date.