Dead Man’s Switch
Engineered deliveryto the people you choose.
After the inactivity window you set (30 days to 12 months) and a 5-week warning cascade, your trusted contacts unlock the vault. They’ve held their keys the whole time, emailed the day you named them. The platform is the gate. The mechanism is engineered, not wishful.
The timeline
ACTIVE ↓ 180 days of inactivity WARNED_1 first warning email ↓ 14 days WARNED_2 second warning, more urgent ↓ 14 days WARNED_FINAL final warning ↓ 7 days TRIGGERED contacts activated, keys usable ↓ 60 days DELETED Living Vault destroyed (Eternal Vault continues)
The cryptographic design
This is the most important paragraph on this page. Your trusted contacts hold their decryption keys from the day you designate them, not at your death. Delivered by email the day you name them. The keys are always cryptographically valid. They could always decrypt your data.
What changes is the platform’s willingness to serve the encrypted data. Until the DMS fires, the server returns 403 for access requests. After, it serves the ciphertext. The keys the contact has been holding for years can now unwrap it.
This is a single boolean, is_active, on the server, toggled by the DMS. Simple, auditable, and crucially: there is no "delivery at death" moment where our email infrastructure or escrow system could fail you at the worst time. The activation email is a courtesy, not a requirement. Your inheritor already has the key.
Why this design
No key delivery at death
The hardest problem in digital legacy is reaching the right people at the worst time. We deliver the keys years early, to decouple key delivery from the trigger event.
Graceful degradation
If Henedo ceases to exist and someone recovers backups from storage, the keys still work. The gating is server-side policy, not cryptographic, it’s a soft floor, not a hard ceiling.
False-trigger protection
5 weeks of warnings. Any login resets. 5 recovery methods (passphrase, recovery key, passkey, Shamir, escrow) ensure you can always log in to cancel.
Engineered delivery vs. wishful delivery
Most digital legacy plans are wishful: "I told my spouse where the password manager is," "my will mentions the safety-deposit box," "my lawyer has a copy of the recovery phrase." Each of these requires a human to do the right thing at the worst moment. Most fail.
Henedo combines per-person keys, a hosted access gate, and a defined download window: each has a different role in the delivery process.
Pre-delivered keys
Each trusted contact is emailed their own access key the day you designate them, while you are alive. The decryption key sits in their hands for years before it is ever needed.
Server-side gate
Until the dead-man's switch fires, the platform refuses to serve ciphertext. The pre-delivered key is useless without the encrypted bytes. After the switch fires, server flips a single boolean. The key in their hands now decrypts the bundle.
60-day window
A defined access period after activation gives heirs time to download what is theirs. After 60 days, the Living Vault is permanently deleted. Separately purchased Eternal archives use their contracted preservation term.
Complete copies and keys
Current Eternal archives store encrypted files in Cloudflare R2. An inheritor holding the complete encrypted archive, its format documentation and the full access key can decrypt independently of hosted delivery. Physical delivery applies only to older contracts that include it.
We are the only platform we are aware of that combines all four. Wills tell. Henedo delivers. See the portability page for the decrypt-without-Henedo recipe, and the journal feature for the voice notes and video messages this mechanism delivers.
FAQ
A mechanism that releases something only if you stop responding. Henedo builds this concept in as Trusted Delivery: after 180 days without a check-in and a 5-week warning cascade, your trusted contacts are activated and can decrypt the vault.
Essentially no. The default takes 180 days of total silence to start, plus 5 weeks of increasingly urgent warnings. Any login, heartbeat, manual check-in, or email click resets the timer. In practice a false trigger requires months of complete disengagement from every device and every inbox.
It does not try to. Henedo never checks health records, obituaries, or anything else about you personally, it only watches whether you check in. Any login counts as a check-in, and you can trigger one manually from the dashboard. The platform will email you warnings starting at 166 days (2 weeks before the first formal warning). You have multiple opportunities to reset the timer.
After the configured inactivity period and warning cascade, trusted contacts receive access to the material assigned to them. The Living Vault access window is 60 days before deletion. Eternal Vault is purchased separately, stores a sealed encrypted cloud archive and follows the preservation and release terms recorded on that purchase.
Yes. Default is 180 days. Eternal Vault owners can set intervals of 1, 2, or 5 years. All timeouts include the 5-week warning cascade before any action.
Get started
Set it up once. Never worry again.
Included in every paid plan. Your vault, your terms, your switch.