Docs / Guides

Using VeraCrypt and Keepsake together

How do I import documents from a VeraCrypt container into Keepsake?

Mount the container in VeraCrypt as you normally would, then point Keepsake's bulk import at the drive letter it appears as. Keepsake reads the files and writes nothing back, so the container is unchanged and can be dismounted afterwards exactly as it was. There is no importer to install: a mounted volume is just a folder.

There is no Keepsake importer for VeraCrypt and there does not need to be one. A mounted container is a drive letter, a drive letter is a folder, and Keepsake already imports folders.

That is worth saying plainly because the usual assumption is that two encryption products must be alternatives. These two are not really competing for the same disk. VeraCrypt encrypts a volume and knows nothing about what is in it; Keepsake encrypts documents and the whole point is that it knows what they are. Running both is a reasonable arrangement rather than a compromise, and this page is how.

Decide what lives where

The split that works:

  • VeraCrypt holds the bulk archive. Scans by the thousand, old tax years, project folders, anything large and rarely opened. It lives on a local disk or an external drive, it is opened deliberately, and its size is not a problem because nothing syncs it.
  • Keepsake holds the documents with dates on them. Passports, visas, driving licences, insurance policies, warranties, tenancy agreements, vehicle documents — the ones somebody has to find in a hurry, often from a phone, sometimes not you.

The dividing question is not how secret is this. It is would anyone need to find this quickly, on a phone, or after I am gone. A container answers none of those, and it was never trying to.

Mount the container

Open VeraCrypt, select the container, and mount it as you normally would.

Mount it read-only if the option is offered: VeraCrypt's Mount Options dialogue has a Mount volume as read-only checkbox. Importing only reads, so nothing is lost by ticking it, and it removes the one real hazard in this whole procedure — if the container holds a hidden volume, writing to the outer volume is what destroys it. A read-only mount cannot.

Note the drive letter it appears as.

Point Keepsake's bulk import at the drive letter

  1. Open Keepsake and unlock your own vault.
  2. Choose Import → Bulk import, then Browse.
  3. Select the mounted drive, or a folder inside it. Keepsake sees an ordinary folder tree and does not know or care that VeraCrypt is underneath it.

Every file that comes across is typed, read, and filed: OCR on the scans, expiry dates extracted where there are any, renewal reminders set from them. Every file that does not come across is listed with its name and the reason — an unsupported type, a size cap, an unreadable file. An importer that loses nine of ninety quietly leaves you believing all ninety arrived.

Import the documents, not the archive. Twelve thousand scans of receipts will import, and they will make the vault worse: the documents that matter stop being the ones you see. Start with the folder you would grab in a fire.

Dismount when the import finishes

Dismount in VeraCrypt as usual. The container is byte-for-byte what it was — Keepsake opened files for reading and wrote nothing back, so there is nothing to undo and no reason not to carry on using it exactly as before.

VeraCrypt's Preferences → Auto-dismount settings are worth setting while you are there, if they are not already: a container that stays mounted all day is a decrypted volume sitting open on a machine somebody else might sit down at, which is the failure that actually happens rather than the cryptographic one nobody has ever performed on you.

Keep the container as your archive

You do not have to choose. Once the paperwork is in Keepsake, the container goes on doing the thing it is genuinely excellent at, and the two do not interact again.

What this arrangement does not give you

  • Keepsake cannot open a container itself. There is no VeraCrypt reader in Keepsake and none planned — mounting is a better answer than an importer here, because VeraCrypt is already installed on the machine that has the container. (Cryptomator is the exception: its vault format is published, so Keepsake reads those vaults directly.)
  • Documents imported into Keepsake are now in Keepsake. They are protected by your Keepsake password and its Recovery Kit, not by the container's password. If you delete them from the container afterwards, the container stops being a backup of them — so either keep both copies, or make sure your backups and exports are real before you delete anything.
  • The container's deniability does not transfer. Keepsake announces what it is, deliberately, and that page says so at length. If the whole reason you use VeraCrypt is the hidden volume, keep it and do not put those documents in Keepsake.

If you would rather move out of VeraCrypt entirely

The procedure is the same one: mount, import, verify, and only then decide what to do with the container. Verify means opening a handful of the imported documents in Keepsake and checking they are what you expect — not counting the rows in the import report. Then keep the container as a cold backup on an external drive rather than deleting it; there is no rush, and a container you no longer mount costs nothing but the disk space.

A fuller side-by-side of what each one does, with the version we checked it against, is on Keepsake vs VeraCrypt.


Was this page helpful?

If something here is missing, wrong, or just unclear, say so — corrections to these pages usually start as a comment.

Leave a comment Ask the community →

Comments

No comments yet — be the first.

Sign in to comment — website account only; your vault never touches it.