SharingPrivacy

Introducing Shared Vaults: End-to-End Encrypted Sharing, No Server in the Middle

The feature you asked for most is here. Share a whole vault with the people you trust, end-to-end encrypted, so everyone opens it with their own Face ID, and you can take access back at any time. No Kinship server ever touches your data.

Some passwords are not really yours alone. The Wi-Fi. The streaming accounts. The utility logins a couple both need. The family's documents. Until now, "sharing" them meant texting a password, reading it aloud, or letting one person hold everything and hoping they are always reachable. Each of those quietly makes a copy you can never take back.

Today we are shipping the most requested feature in Kinship Vault's history: shared vaults. Invite the people you trust into a vault, and each of them opens it on their own device, with their own biometrics. It is end-to-end encrypted from the first second, there is no shared master password to pass around, and if things change, you can revoke access for real.

Key takeaways

  • Share an entire vault, logins, documents, notes, with family, a partner, or a small team.
  • End-to-end encrypted. The vault's key is wrapped to each member's identity; everything in the cloud is ciphertext. Kinship has no server, and Apple only relays ciphertext.
  • Everyone uses their own Face ID or Touch ID. No shared master password, no plaintext sent to anyone.
  • The owner can remove a member, which rotates the key so the removed person is locked out of everything written afterward.
  • Only the vault you choose is shared. Your other vaults stay private and invisible.

How sharing works, without a middleman

A shared vault is a normal Kinship vault, one of the several you can now keep, that a few people can open. What makes it safe is what it does not do: it never hands your data, or a usable key, to any server.

When you create one, your device mints a fresh encryption key for that vault, its content key. To let someone in, that key is wrapped (sealed) individually to that person's public identity key, a key their device generated and only their device can undo. The sealed copies are stored in the cloud so members' devices can pick them up, but a sealed key is useless to anyone else, including Apple and including us.

From then on, everything the vault syncs, every password, note, and document, is encrypted with that content key before it leaves the device. Apple's iCloud is used purely as a dumb, encrypted relay: it carries opaque ciphertext and a handful of public keys between members, and can read none of it. There is no Kinship Vault server in the path at all.

Everyone in a shared vault holds the key. The cloud only ever holds the locked box, and the sealed copies of the key that only each member can open.

Inviting people

Open Manage Vaults, choose Create Shared Vault, give it a name and look, and tap Create & Invite. Kinship hands you the standard iOS or Mac share sheet, so you can send the invitation however you already share things. When the other person accepts on their device and you grant them access, the vault's key is wrapped to their identity, and the shared vault appears alongside their own.

There is no account to create, no password to dictate, no "here, memorize this." Each member unlocks the shared vault with the same Face ID or Touch ID they use for their personal one.

Waiting to join? After accepting, a member may briefly see a "waiting for access" screen until the owner opens the vault to grant it. Once granted, the vault and its contents appear, and its logins become fillable with the member's own biometrics.

Taking access back, for real

Plans change. Someone moves out, a contractor's job ends, a relationship shifts. In most tools "removing" a person just hides a row while every secret they ever saw stays valid forever. Kinship does it properly.

When the owner removes a member, the vault's content key is rotated, a brand-new key is generated and re-wrapped only to the people who remain. Anything written after that point is sealed with a key the removed person never had. This is the difference between hiding someone from a list and actually cutting them off.

A note on what sharing can and cannot undo. Revocation locks a former member out of future contents. It cannot un-see a password they already read and memorized, no system can, so treat a removal as the moment to also rotate any truly critical passwords that person knew. Kinship's generator makes that a few taps.

Only what you choose, nothing more

Sharing one vault shares exactly that vault. The people you invite never see your personal or work vaults, and they never learn they exist. And because a sensitive vault is intentionally unshareable, the things you lock behind that extra wall can never be handed out, even by accident.

The old wayA shared vault
Text or dictate the passwordInvite; each member unlocks with their own Face ID
A plaintext copy exists foreverEnd-to-end encrypted; the cloud sees only ciphertext
"Removing" someone hides a rowRemoval rotates the key and locks them out
Update a password, tell everyone againChange it once; every member's app updates

Built on the same promise

Shared vaults do not bend Kinship Vault's trust model; they extend it. There is still no Kinship server, still zero-knowledge, still on-device encryption. We wrote a deeper, plain-English walkthrough of the cryptography, identity keys, sealed keys, the signed member list, and how revocation rotates everything, in how shared-vault encryption actually works.

If you want the practical guides instead: sharing with your family, and shared vaults for a small team.

Share what you mean to. Keep the rest yours.

Create a shared vault, invite the people you trust, and give everyone their own key, with the power to take it back. End-to-end encrypted, on iPhone, iPad, and Mac.

Explore Kinship Vault