Dead Man’s Switch

Engineered deliveryto the people you choose.

After the inactivity window you set (30 days to 12 months) and a 5-week warning cascade, your trusted contacts unlock the vault. They’ve held their keys the whole time, emailed the day you named them. The platform is the gate. The mechanism is engineered, not wishful.

The timeline

ACTIVE
  ↓ 180 days of inactivity
WARNED_1       first warning email
  ↓ 14 days
WARNED_2       second warning, more urgent
  ↓ 14 days
WARNED_FINAL   final warning
  ↓ 7 days
TRIGGERED      contacts activated, keys usable
  ↓ 60 days
DELETED        Living Vault destroyed (Eternal Vault continues)

The cryptographic design

This is the most important paragraph on this page. Your trusted contacts hold their decryption keys from the day you designate them, not at your death. Delivered by email the day you name them. The keys are always cryptographically valid. They could always decrypt your data.

What changes is the platform’s willingness to serve the encrypted data. Until the DMS fires, the server returns 403 for access requests. After, it serves the ciphertext. The keys the contact has been holding for years can now unwrap it.

This is a single boolean, is_active, on the server, toggled by the DMS. Simple, auditable, and crucially: there is no "delivery at death" moment where our email infrastructure or escrow system could fail you at the worst time. The activation email is a courtesy, not a requirement. Your inheritor already has the key.

Why this design

No key delivery at death

The hardest problem in digital legacy is reaching the right people at the worst time. We deliver the keys years early, to decouple key delivery from the trigger event.

Graceful degradation

If Henedo ceases to exist and someone recovers backups from storage, the keys still work. The gating is server-side policy, not cryptographic, it’s a soft floor, not a hard ceiling.

False-trigger protection

5 weeks of warnings. Any login resets. 5 recovery methods (passphrase, recovery key, passkey, Shamir, escrow) ensure you can always log in to cancel.

Engineered delivery vs. wishful delivery

Most digital legacy plans are wishful: "I told my spouse where the password manager is," "my will mentions the safety-deposit box," "my lawyer has a copy of the recovery phrase." Each of these requires a human to do the right thing at the worst moment. Most fail.

Henedo combines per-person keys, a hosted access gate, and a defined download window: each has a different role in the delivery process.

Pre-delivered keys

Each trusted contact is emailed their own access key the day you designate them, while you are alive. The decryption key sits in their hands for years before it is ever needed.

Server-side gate

Until the dead-man's switch fires, the platform refuses to serve ciphertext. The pre-delivered key is useless without the encrypted bytes. After the switch fires, server flips a single boolean. The key in their hands now decrypts the bundle.

60-day window

A defined access period after activation gives heirs time to download what is theirs. After 60 days, the Living Vault is permanently deleted. Separately purchased Eternal archives use their contracted preservation term.

Complete copies and keys

Current Eternal archives store encrypted files in Cloudflare R2. An inheritor holding the complete encrypted archive, its format documentation and the full access key can decrypt independently of hosted delivery. Physical delivery applies only to older contracts that include it.

We are the only platform we are aware of that combines all four. Wills tell. Henedo delivers. See the portability page for the decrypt-without-Henedo recipe, and the journal feature for the voice notes and video messages this mechanism delivers.

FAQ

Get started

Set it up once. Never worry again.

Included in every paid plan. Your vault, your terms, your switch.