What the encryption passphrase does
Each file has its own random encryption key. Your encryption passphrase creates a browser-only key that protects those file keys. VaultDrop receives encrypted files and encrypted file keys, not the readable files or passphrase.
Your account password and encryption passphrase have different jobs. The account password signs you in. The encryption passphrase unlocks file contents.
What VaultDrop stores
- Encrypted file contents and encrypted file keys.
- A random salt used by your browser to derive the encryption key.
- An encrypted check that lets your browser identify a correct passphrase.
- An encrypted recovery copy of the passphrase, protected by your 12-word recovery phrase.
- Your acknowledgement of the current recovery explanation.
VaultDrop does not store the readable encryption passphrase or recovery phrase.
If you forget the encryption passphrase
Use the 12-word recovery phrase from your recovery kit. Your browser uses it to recover the old passphrase locally, unlock the existing keys, and protect them with a new passphrase.
The recovery phrase and new passphrase stay in the browser. VaultDrop receives only newly encrypted key material.
Recover an encrypted vaultIf you lose both secrets
If both the encryption passphrase and recovery phrase are lost, existing encrypted files cannot be decrypted. Account access, email verification, 2FA, support checks, or billing records cannot recreate the missing cryptographic secret.
VaultDrop can help restore account access, but it cannot make unreadable files readable without one of those secrets.
Why security questions are not used
Answers such as pet names, schools, birthdays, or family details can often be guessed or discovered. They can help prove identity only weakly, and identity proof alone cannot recreate an encryption key.
VaultDrop uses a high-entropy recovery phrase instead. Anyone who obtains it may be able to recover the encrypted vault, so support will never ask a user to reveal it.
How to store the recovery phrase
- Print the recovery kit and store it with important business records.
- Save it in a reputable password manager.
- Do not store the only copy inside VaultDrop.
- Do not send it by ordinary email or messaging.
- Do not share it with VaultDrop support.
Business account recovery
Workspace-owner recovery is not currently enabled. Each account holder controls their own recovery phrase. An organization-managed recovery option will require explicit enrollment, restricted owner permissions, and audit logging before it can be offered safely.