Portability & independent recovery
Your vault, decryptable with or without us.Keep the archive. Keep the keys.
Your data should come with you. Henedo provides open export formats and an offline decryptor. Eternal Vault adds a separately purchased encrypted cloud archive that you prepare and seal in your account. Independent recovery requires a complete archive copy and the corresponding keys; retain both before you need them.
Open formats, by design
Every vault export is an OAIS-style bundle composed of three parts: a manifest.json describing the file tree, one ciphertext blob per file, and a printable crypto-spec PDF listing every algorithm and parameter we use. There is no proprietary container, no closed binary format, and no Henedo-specific decoder.
Journal entries and the 1,000-prompt Life Story export as plain UTF-8 markdown bundles, one file per entry or answer. Voice and video answers export as standard WebM/Opus or MP4/AAC and MP4/H.264, opaquely the same files your browser recorded, decryptable with the same FEK-under-MK procedure as everything else in the vault. No special viewer required.
With your passphrase, your device-bound Account Secret Key (ASK), and the export bundle, you (or your heirs) can decrypt the entire vault on any modern computer running standard cryptographic libraries. We test this end-to-end every build.
The decrypt-without-Henedo recipe
Keep these instructions with your complete export, and store its keys securely. The exact parameters live in the crypto-spec PDF inside the bundle, and the full encryption architecture (AES-256-GCM, Argon2id, post-quantum signatures) is documented page-by-page on the security page, but the algorithm shape is public:
1. KEK = Argon2id(passphrase + ASK_hex, salt, t=3, p=4)
→ HKDF-SHA-256('henedo-kek-v<N>', 32 bytes)
The Argon2id memory cost and HKDF label depend on your account's
KDF version (current default v3 = 128 MiB); the crypto-spec.txt
inside your export bundle states the exact parameters for YOUR
account. Alternatively, your Recovery Key derives the unwrap key
with no Argon2id at all, that path is version-independent.
2. MK = AES-256-GCM.decrypt(KEK, EMK, mk_iv)
3. For each encrypted file in the manifest:
FEK = AES-256-GCM.decrypt(MK, EFEK, fek_iv)
plaintext = AES-256-GCM.decrypt(FEK, ciphertext, file_iv)
4. Verify the file_name is decrypted with MK using the encrypted_file_name + file_name_iv columns.
The only library dependencies are AES-256-GCM, Argon2id, and HKDF-SHA-256.
All three have reference implementations in @noble/* and Web Crypto.Proving a file is genuinely yours is portable too. Anything your family opens from an Eternal Vault can be saved alongside a small .proof file carrying that document's fingerprint, its place in the vault's signed Merkle tree, the seal date, and all three signatures (Ed25519, ML-DSA-65 and SLH-DSA) with the algorithms named in plain text. A grandchild in eighty years can check that one file on its own — without the rest of the vault, and without us.
Download the standalone decryptor
We ship a single-file, dependency-free HTML page that implements the recipe above end-to-end. It runs entirely offline: open it in any modern browser, pick your export zip, enter your passphrase and Account Secret Key, and your vault unlocks on your local machine. No Henedo server, code, or domain is contacted.
The same file is automatically embedded inside every export bundle, so heirs always have an offline copy alongside the data. You can also keep an extra copy alongside the complete encrypted export on storage you control.
Inspect the file, audit the embedded crypto, save it offline. Web Crypto API + Argon2id are inlined; nothing else is required.
Encrypted cloud storage, with a separate archive purchase
Eternal Vault is $699 once for 100 GiB with a 100-year preservation term. Payment creates an archive purchase in your account. Open Eternal Vault in the dashboard, upload files, choose inheritors and seal an encrypted snapshot. The current storage backend is Cloudflare R2.
The seal binds the archive manifest and integrity proofs. Current purchases use complete inheritor keys prepared for email delivery. Save the keys securely so you can share them if an email does not arrive. A membership is not required to purchase an Eternal archive.
Physical delivery and existing contracts
The current cloud purchase does not include M-Disc delivery or an invested preservation fund. Older purchases that include physical delivery retain their contracted scope. Check the order and fulfillment status of those purchases in your account; a sealed cloud archive is not evidence that a disc has shipped.
An offline copy must contain the complete encrypted archive, its format documentation and the corresponding full key. A partial disc or a key by itself cannot reconstruct missing files.
Continuity by design
Independent recovery depends on what you and your inheritors already hold:
- Archive: retain every encrypted file and the manifest from the complete export.
- Keys: keep the full decryption material securely, separately from the archive copy.
- Reader: save the offline reader and format documentation alongside the data.
Cloud access requires an operating service. A purchased preservation term does not prove that a century of operations, a separate custodian or a recurring hardware-refresh program is already in place.
Free export. Free deletion. Free always.
From your Settings page you can:
- Export your full vault as the OAIS bundle described above. No fee, no review queue, no rate limits beyond what is needed to keep the system stable.
- Delete your account and all associated ciphertexts under GDPR Article 17 right-to-erasure. We confirm by email, then irreversibly destroy the data on our side. See the privacy policy for the exact retention schedule.
- Keep an independent copy of the complete export and its offline reader, with the required keys stored securely. Physical-delivery terms apply only to older purchases that include them.
We do not gate exports behind tier upgrades. We do not charge per-MB egress. Customer confidence costs us less than customer churn.
How this protects you
The Living Vault and hosted Eternal access require the service to operate. A complete independent archive copy and its keys let you recover the content with the documented format and standard tools, without relying on the hosted access page.
FAQ
An inheritor who already holds the complete encrypted archive, its format documentation, and their full access key can decrypt it independently. A key alone cannot recover files that were never downloaded. Current Eternal purchases use encrypted cloud storage; physical delivery applies only to existing contracts that include it.
From Settings → Export. We hand you an OAIS-style bundle: a manifest.json describing every file, the ciphertext blobs, and a copy of the crypto spec PDF. Your passphrase plus your device-bound Account Secret Key (ASK) decrypts it offline. There is no proprietary container, no per-MB egress fee, and no review queue.
Export and account deletion have no separate fee. Keep your complete export and its decryption keys in a safe place. The current Eternal purchase is a cloud archive and does not include a physical disc.
A zip bundle containing: (1) manifest.json with the file tree, encrypted file names, IVs, and key wrapping metadata; (2) one ciphertext blob per file, named by its content hash; (3) crypto-spec.pdf with the exact AES-256-GCM, Argon2id, and HKDF parameters used. Anyone with a competent crypto library can decrypt the bundle independently.
Eternal Vault is a separate $699 one-time purchase for 100 GiB with a 100-year preservation term. After payment confirmation, open Eternal Vault in your dashboard, add files, choose inheritors and seal. Files are encrypted before upload to Cloudflare R2. Inheritor keys are prepared for email delivery; keep a secure backup in case an email does not arrive.
Long-term preservation requires maintaining readable copies as technology changes. A purchased preservation term does not mean a hardware-refresh cycle or independent archival-custody operation has already been established. The current implementation is encrypted cloud storage, a sealed manifest and portable cryptographic verification. Keep a complete independent copy and the keys needed to open it.
The signing public key is embedded in every Henedo build, so any cached copy of the app remains independently verifiable. The signed manifests we have already published are public records. Our wind-down plan includes mirroring the manifest log to a successor archive so future auditors can verify any historical build.
Because lock-in is a fair concern, and the right answer is to remove it. A vault is only worth as much as the user's confidence that they can leave with their data intact. We engineer that confidence into the product, not into a privacy policy.
Get started
The vault you can leave with.
Open formats. Free export. Complete encrypted archives and the keys to open them.