Cold Vault Protocol
Because Apex never holds a recoverable copy of your vault, backup and recovery are your responsibility. The Cold Vault Protocol is the optional, opt-in way to create a backup you control completely.
Why it works this way
Section titled “Why it works this way”There is no escrow and no backdoor. If Apex could restore your vault, so could anyone who compromised Apex — which would reintroduce exactly the server-side risk the design removes. So the only backup that exists is one you create and store.
How it works
Section titled “How it works”- You initiate an export from the app. Nothing is backed up silently or automatically.
- The vault is encrypted on-device into a single portable file, using a key derived from your master phrase (and/or a separate backup passphrase you choose).
- You store the file wherever you want — a hardware drive in a safe, a printed/QR cold copy, a trusted offline location. Apex never receives it.
- To recover, you import the file on a new device and unlock it with the phrase that sealed it.
What this means for you
Section titled “What this means for you”- You can survive a lost phone — restore from your backup onto a new device.
- No third party is in your recovery path — not Apex, not a cloud account.
- The trade-off is real: if you lose both your master phrase and every backup, the vault is unrecoverable. That is the cost of there being no backdoor.
Recommended practice
Section titled “Recommended practice”- Create a Cold Vault export after your first meaningful set of entries, and refresh it periodically.
- Store at least one copy offline and physically separate from your phone.
- If you use a separate backup passphrase, record it somewhere durable and independent — losing it is the same as losing the backup.
Related
Section titled “Related”- Security model — primitives and key custody.
- Threat model — what a lost phrase does and does not expose.