Feature

The encrypted vault

Everything else Keepsake does sits on top of one promise: your documents are encrypted on your device, with keys only you hold, in a format that is documented and yours forever.

The problem

Family documents end up scattered across camera rolls, email attachments, desk drawers and someone else's cloud. The digital copies are the sensitive kind — passports, contracts, medical records — yet they usually sit unencrypted, or encrypted with keys a company controls. If that company is breached, subpoenaed or shut down, your privacy (or your access) goes with it.

And the tools that do encrypt properly are built for engineers, not for the person in your family who actually keeps the documents.

How Keepsake solves it

🔐Encrypted before it exists anywhere

Files are encrypted with AES-256-GCM the moment they enter the vault. The key comes from your password via Argon2id — resistant to GPU cracking rigs, not just casual guessing.

🔑A real answer to "I forgot"

Vault creation prints a Recovery Kit: 24 words that can restore access. Keep it in a drawer or a bank locker. It is always free, because safety is never an upsell.

🧾History that cannot be rewritten

Every vault action is recorded in a hash-chained audit log the apps can verify. If an entry were altered, the chain breaks visibly — even we could not rewrite it.

Under the hood — the KVF2 format

  • Every encrypted record is framed as KPS2: magic, version, flags, a random 96-bit nonce, then AES-256-GCM ciphertext with its authentication tag. Tampering fails authentication; nothing decrypts silently wrong.
  • Master key derivation: Argon2id with per-vault salt; the key never leaves your device and is never written to disk unwrapped.
  • The recovery phrase is BIP-39 — 24 words encoding an independent unlock path, generated locally and shown exactly once.
  • One documented format, three independent implementations (C#, Kotlin, TypeScript) proven byte-compatible by shared test fixtures — a vault created on Windows opens identically on Android and the web.

Trust through specificity: the full crypto design is documented on the security page.

Questions

Can Keepsake or anyone at the company decrypt my vault?

No. The encryption key is derived from your password on your device. We never see the password, the key, or the ciphertext — vaults are stored on your devices and your own cloud, not on our servers.

What if I lose my password AND the Recovery Kit?

The data is unrecoverable — by anyone. That is the honest cost of real encryption, and it is why the Recovery Kit is printed at setup and free forever.

Last verified — by dotnet test Keepsake/KeepsakeVault.Tests. Every claim on this site is listed, with its evidence, in the claim ledger.