A Sensitive Vault Behind Its Own Password: Extra Protection for What Matters Most
Most of your vault should be easy to reach: unlocked with a glance, recoverable if you lose your phone. But a few things deserve a second wall. A sensitive vault is sealed behind its own password, cannot be shared, and is deliberately out of reach of your recovery phrase. No backdoor, not even for us.
Security is not one setting turned up to maximum for everything. The passwords you use twenty times a day should be frictionless and easy to get back. But almost everyone has a short list of things that are different: a document, a few photos, a login whose exposure would genuinely hurt. For those, convenience is not the priority; a second wall is.
That is what a sensitive vault is for. It is one of the separate vaults you can now keep, but hardened on purpose: it has its own password, it can never be shared, and it is walled off from the recovery paths that protect the rest of your data. You are trading recoverability for absolute privacy, deliberately, with your eyes open.
Key takeaways
- A sensitive vault is sealed behind its own password, on top of Face ID or Touch ID.
- Your 24-word recovery phrase cannot reach it. Those words bring back your other vaults, never this one.
- It cannot be shared with anyone, so its contents can never be handed out, even by accident.
- No backdoor, not even us. You save a dedicated recovery code at setup; if both the password and that code are lost, no one can open it.
What makes it "sensitive"
Setting up a sensitive vault is a short, three-step ritual, and each step spells out a trade-off you are choosing:
| What you set | What it means |
|---|---|
| Its own password | The vault will not open on biometrics alone. You enter a password only you know, every time. |
| Out of the recovery phrase | Your 24 words rebuild your other vaults, never this one, so a recovered phrase can never expose it. |
| Cannot be shared | A sensitive vault has no invite. Its contents are for you alone. |
| Its own recovery code | You save a separate code and confirm you have stored it safely. That code, plus your password, is the only way back in. |
The absence of a backdoor is the feature. Because there is no master way in, no one, not an attacker, not a court order to us, not us on our best day, can open it without your password.
The trade-off, stated plainly
A sensitive vault gives up the safety nets on purpose. There is no "we'll help you recover it" path, because such a path would also be a way in for someone who is not you. This is the same logic behind zero-knowledge design, taken to its strictest conclusion.
What belongs in one (and what does not)
A sensitive vault is a small, sharp tool, not a second home for everything.
- Good fits: a handful of financial or legal documents, genuinely private photos, one or two logins whose exposure would be serious. Things you would not want anyone to reach even with your unlocked phone in their hand.
- Leave in your normal vault: everyday logins, IDs you use often, anything your family might one day need. Those belong where they stay convenient and recoverable.
Think of your vaults as concentric walls: your normal vault for daily life, a shared vault for what your household holds together, and a sensitive vault as the innermost room, opened only by you, only with a password, with no spare key anywhere.
An innermost room, with no spare key.
Put your most private things behind a second wall: a sensitive vault with its own password, unshareable, with no backdoor. Alongside your everyday and shared vaults, on iPhone, iPad, and Mac.
Explore Kinship Vault