Family Vault
The house deed, the kids' vaccination records, grandma's prescriptions — family documents belong to the family. Keepsake shares them through your own cloud with permissions enforced by keys, not by a company's access-control list.
How do Keepsake family permissions work?
Family Vault has five roles — Owner, Co-owner, Editor, Viewer and Deputy — enforced by key-wrapping rather than by a server. The family key and each category key are sealed to the members who should hold them, so a member without the box holds ciphertext and nothing else. Writing is different: a category key also encrypts, so Viewer is an interface role, and Keepsake labels which limits are cryptography and which are the app.
The problem
Families share documents today by WhatsApp-ing photos of passports — because every proper solution routes the family's most sensitive papers through a vendor's servers, readable by that vendor, priced per seat, gone when the subscription lapses.
And "shared with family" should not mean "everyone sees everything": the teenager needs their own ID, not the parents' financial records.
How Keepsake solves it
👨👩👧👦One vault, six people
A shared family vault lives in a cloud folder the family already owns. Each member joins from their own device with their own password and recovery kit.
🗂️Permissions by category
Finance for the adults, IDs for everyone, medical for whoever needs it. Access is granted per category — and revoking it actually removes the keys.
🚨Emergency access built in
A sealed in-case-of-emergency kit: a designated person plus a printed share can unlock the vault when it matters — offline, lawyer-drawer compatible.
Under the hood — keys, not ACLs
- Each member has a keypair; the family key is wrapped to each member's public key. Category keys are wrapped to the members with access — possession of keys is the permission system.
- No server evaluates permissions, so no server can be tricked, subpoenaed or breached into overriding them.
- Emergency access is an offline 2-of-3 Shamir-style split of the master key: you, your designated person, and a printed copy.
- Built on the same op-log sync engine as Sovereign Sync — members' edits merge deterministically across all devices.
- The five roles and the table below come from one file,
shared/roles.json, read by the Windows app, the Android app, the web app and this page. A test suite on each fails if any copy drifts, because a permissions table that disagrees with the software is worse than no table.
Trust through specificity: the full crypto design is documented on the security page.
Five roles, and what actually enforces them
Every member is one of five roles. They are presets over the key-wrapping rather than a separate permission system — a role decides which sealed boxes get written for somebody, and the boxes decide what they can open.
The second column is the part most permission tables leave out. Some of these limits are cryptography and some are our own interface, and the difference matters when you are deciding what to grant. Where a row says Cryptography, the member does not hold the key and no software — ours, a modified build, or somebody else's reader — can help them. Where it says The app, they hold the key and Keepsake simply does not offer them the action.
Owner
Created the family. Holds the family key and every category key, adds and removes members, and is the only member who cannot be removed.
Co-owner
A second adult with the same reach as the owner. Exists because a family whose only full member loses their phone is a family locked out of its own documents.
Editor
Reads and adds documents in the categories they have been granted, and nothing else. The usual role for a partner who files the insurance but has no reason to touch the will.
Viewer
Opens and reads the categories they have been granted. The apps offer no way to add or change a document. Right for a teenager who needs their own passport on a phone.
Deputy
Holds one share of the emergency split and no keys at all. A deputy cannot open the vault today; they can help open it when the emergency procedure runs. The person you name in a will, not a member of the household.
| Capability | Enforced by | Owner | Co-owner | Editor | Viewer | Deputy |
|---|---|---|---|---|---|---|
| Open the family vaultThe family key is sealed to each member's X25519 public key. A member with no fk_box for their id cannot derive the op-log key, so the shared folder is opaque to them — that is what makes a deputy safe to name years in advance. | Cryptography | Yes | Yes | Yes | Yes | No |
| Read documentsEach category has its own content key, sealed separately to the members who have that category. A member without the box holds ciphertext and nothing else. | Cryptography | Every category | Every category | Granted categories only | Granted categories only | None |
| Add or change documentsA category key is symmetric: whatever decrypts also encrypts. Viewer is therefore an interface role — Keepsake's apps offer a viewer no way to write, and every edit is attributed to the member who made it, but a member holding the key is not cryptographically stopped from writing. If you need that guarantee, do not grant the category. | The app | Yes | Yes | Yes | No | No |
| Add a memberSealing the family key to a new public key needs the family key, which every member above deputy holds. The restriction to owners and co-owners is enforced by the apps, and every membership change is a manifest change that every device sees. | The app | Yes | Yes | No | No | No |
| Remove a memberRemoval rotates the family key and every category key the departing member held, then re-seals to whoever remains. Any full member could perform the rotation; the apps allow it only to owners and co-owners, and never against the owner. Copies a removed member already downloaded cannot be recalled — nothing can do that. | The app | Yes | Anyone except the owner | No | No | No |
| Grant a category to somebodyGranting means sealing that category's key to the member, so it can only be done by somebody who already holds the key. An editor cannot widen their own access to a category they were never given. | Cryptography | Yes | Yes | No | No | No |
| Revoke a categoryRevocation drops the member's box and rotates the category key for everyone who keeps access, so future documents are unreadable to them. Same reach as granting; the apps restrict who is offered it. | The app | Yes | Yes | No | No | No |
| Rotate the family keyBumps the manifest epoch and re-seals the family key to the remaining members. Restricted to owners and co-owners in the apps. | The app | Yes | Yes | No | No | No |
| Hold an emergency shareThe emergency split is 2-of-3 Shamir over the master key: you, your deputy, and a printed share. One share alone reconstructs nothing, which is what lets a deputy hold theirs for years without holding access. | Cryptography | Yes | Yes | No | No | Yes |
The honest reading of the two The app rows on writing and membership: a category key is symmetric, so whatever decrypts also encrypts. A viewer who ran a modified build could write to a category they hold. Every change is attributed to the member who made it and every device sees it, which is what a household needs — but if you need a guarantee rather than a convention, the answer is not to grant the category at all. We would rather print that here than let you find it out later.
Questions
When does Family Vault ship?
It is the current top item in development, right behind the launch of the apps themselves. The Family plan price (£29/yr, up to 6 members) is already locked in on the pricing page, alongside Premium at £19/yr and Teams at £79/yr per 10 seats.
Does every family member need their own account?
There are no accounts anywhere in Keepsake. Each member has their own vault password and recovery kit on their own devices; membership is a key exchange, not a signup.
Can a Viewer really not edit a document?
Keepsake's apps offer a viewer no way to add or change anything, and every edit is attributed to whoever made it. But a category key both decrypts and encrypts, so a viewer running a modified build is not stopped by cryptography — only by the app. That is why the permissions table labels each row with what enforces it. If you need a hard guarantee rather than a household convention, do not grant that category.
What is a Deputy, and can they read my documents?
A Deputy holds one share of the 2-of-3 emergency split and no vault keys at all — no family key, no category keys. They cannot open anything today, which is exactly what makes it safe to name somebody years in advance. When the emergency procedure runs, their share plus one other reconstructs the master key.
Why have both an Owner and a Co-owner?
Because a family whose only full member loses their phone is a family locked out of its own documents. A co-owner has the owner's reach — adding members, granting and revoking categories, rotating keys — with one exception: they cannot remove the owner. There is exactly one owner and they cannot be removed by anybody.