Complete guide

Security, release, executors, and every feature.

A plain-English guide to what the vault stores, how dual-custody security works, what happens during release, and how beneficiaries, executors, recovery, and legal tools fit together.

Overview

What AevumSecure does

AevumSecure is a private emergency vault for the accounts, documents, codes, files, and instructions your people may need if you cannot help them yourself.

Step 01

Add your important things

Add passwords, recovery codes, documents, photos, and letters. Files are encrypted before they leave your device.

Step 02

Choose who receives what

Name trusted people and assign items one by one. You can change beneficiaries anytime.

Step 03

We check in on you, gently

Pick a schedule. We send reminders by email and SMS, and simply logging in counts as a check-in.

Step 04

If needed, release is slow

Repeated silence starts escalation, optional executor confirmation, and a cooling-off period. Logging in stops everything.

Features

Everything you can set up

The core vault works without a lawyer. The legal and executor tools are available when you want a more formal handoff.

Vault contents

Store the things people actually need when they cannot ask you.

  • Passwords, PINs, account notes, and recovery instructions.
  • 2FA backup codes, authenticator keys, and security-key instructions.
  • Important documents, letters, rich-text instructions, photos, videos, and files.
  • CSV imports from password managers such as 1Password, LastPass, and Bitwarden.
People and permissions

Control who gets access, down to the individual item.

  • Primary beneficiary for the main handoff.
  • Secondary beneficiaries for specific items.
  • Item-level assignments, so each person sees only what you chose.
  • Optional executor or attorney checkpoint before release.
Check-ins and release settings

Tune the timeline to your life and risk level.

  • Check-in schedules from frequent to cautious.
  • Email reminders everywhere, with optional SMS where supported.
  • Release tiers from 48 hours to 270 days.
  • Logging in cancels any active release before access opens.
Account and support tools

Security controls and practical help around the vault.

  • Passkeys, email/password fallback, and optional authenticator-app 2FA.
  • Multiple passkeys for backup devices.
  • A 48-hour recovery-key process for account recovery.
  • A public concierge that explains the product but cannot read encrypted vault items.
Files and media

Keep more than passwords, while preserving confidentiality.

  • Files are encrypted in your browser before upload.
  • Images, videos, audio, and documents can be attached to vault items.
  • Beneficiaries view released media through the secure portal.
  • Current upload limit is 50 MB per file.
Optional legal handoff

Use the vault on its own, or help a lawyer reference it formally.

  • Digital Estate ID for referencing the vault.
  • Printable will-clause pack for a qualified lawyer to review.
  • Optional attorney/executor workflow.
  • AevumSecure is software, not a law firm, and does not replace a will.

What you can keep

Account passwords

Email, banking, mobile money, domains, and social logins with the notes needed to use them.

2FA & recovery codes

Backup codes and recovery steps, so a password is not the end of the road.

Important documents

Insurance, property records, ID copies, and files people search for under pressure.

Photos & videos

A family archive that should not vanish with one device or cloud login.

Letters to loved ones

Private notes for specific people, kept sealed until release.

Trust & security

How we protect the vault

The security model is built around two locks, short sessions, explicit authorization, and ongoing hardening.

Dual custody, in plain English

Your vault uses two lock layers: a key derived from your passkey or password, and a managed key layer around each item. Normal vault access needs both.

Separate keys per item

Each vault item has its own encryption key. One item should not expose another, and released access is prepared item by item.

Strong sign-in

Passkeys are the preferred sign-in method. Email and password can be used with an authenticator app, and sessions expire after 15 minutes of inactivity.

Release is not instant

A missed reminder does not open anything. Release needs repeated silence, escalation, optional executor confirmation, and a cooling period.

Reviewed and tested paths

We test and review the code paths around sign-in, encryption, recovery, beneficiary access, and release, then keep hardening them as the product grows.

Honest limits

No system is perfect. We do not promise magic access recovery. If you lose every device and your recovery key, we cannot recover your vault.

What we keep validating

Security claims only matter if the critical paths behave under pressure, so the release and recovery flows are treated as core product surfaces.

Code paths we keep validating

Testing and review focus on sign-in, session expiry, encryption and decryption, recovery, beneficiary access, release cancellation, and executor approval.

Release-specific checks

We validate missed check-ins, reminder escalation, executor windows, cooling periods, cancellation on login, item assignments, and 90-day access expiry.

No silent shortcut

Support cannot bypass your key, skip your release timeline, or hand vault contents to someone who asks. Those limits are part of the security model.

Security keeps improving

As features change, we keep reviewing assumptions, tightening flows, and hardening the product instead of treating launch as the finish line.

Release process

What happens if you stop responding

Inactivity alone never opens the vault. Release is a staged process with reminders, checks, and time to cancel.

  1. 1

    You miss repeated check-ins

    One missed email changes nothing. The system waits through your grace period, sends more reminders, and escalates only on the schedule you configured.

  2. 2

    Release is initiated

    Your primary beneficiary is invited or notified. If they need an account, they create one before any vault item can be opened.

  3. 3

    Executor confirms, if required

    Your executor or attorney receives a confirmation page with a button. This avoids accidental approval from email link scanners.

  4. 4

    The cooling period runs

    Your chosen release tier controls the wait: 48 hours, 14 days, 30 days, 90 days, or 270 days. Logging in during this window cancels the release.

  5. 5

    Access opens only after approval

    Beneficiaries enter the portal and see only assigned items. Sensitive fields stay hidden until deliberately revealed.

  6. 6

    Access expires

    Beneficiary access is a handoff window, not permanent access. Released access expires after 90 days.

Release tiers

You choose how long the cooling period lasts.

TierTimingUse case
Urgent48 hoursFastest handoff for high-risk situations.
Rapid14 daysFrequent check-ins with a meaningful safety window.
Fast30 daysBalanced speed and caution.
Standard90 daysDefault recommendation for most people.
Cautious270 daysMaximum protection against false positives.

Executor response windows

If enabled, executor timing scales with the release tier.

TierWindowReminder
Urgent1 day12 hours
Rapid3 days1.5 days
Fast7 days3.5 days
Standard14 days7 days
Cautious30 days15 days

Beneficiaries & executors

Who is involved

The system separates recipients from reviewers. Someone can confirm a release without seeing vault contents.

Primary beneficiary

The main person who receives access after release, often a spouse, sibling, child, or closest family member.

Secondary beneficiaries

People who receive only the items assigned to them. Useful for business partners, relatives, or specific account owners.

Executor

A trusted person or attorney who can confirm a release should proceed. They do not see inside your vault.

Beneficiary portal

The secure portal where released recipients sign in, re-enter their password to decrypt items, and access only their assignments.

Recovery & limits

How to avoid locking yourself out

A secure vault has to be recoverable by you, but not easy for someone else to take over.

Add more than one passkey

Register your phone, laptop, or a hardware security key so one lost device does not lock you out.

Write down your recovery key

The recovery key is shown during setup. Keep it somewhere safe and offline.

Recovery has a 48-hour wait

Recovery deliberately takes time and sends warnings first, so account takeover cannot happen quietly.

Logging in always stops release

If a release starts while you are alive and active, signing in cancels it before access opens.

The hard limit is intentional

If every passkey, device, password path, and recovery key is gone, AevumSecure cannot simply open your vault for you.

Important limits

  • AevumSecure does not replace a lawyer, a will, or estate advice.
  • The public concierge is for product questions. Do not paste vault secrets into it.
  • Current encrypted file uploads are capped at 50 MB per file.
  • SMS support depends on region and opt-in. Email remains the reliable baseline.
  • Security is never “done”. We keep testing, reviewing, and improving the system.

FAQ

Common questions

Short answers to the questions people usually ask before creating a vault.

What exactly does dual custody mean?

It means normal vault access depends on two layers: your passkey or password-derived key, plus a managed key layer around the item. The goal is to avoid a single easy path to the vault while still allowing the release workflow you configured.

Can an executor read my vault?

No. The executor is a checkpoint, not a recipient. They can confirm that release should proceed, but they do not receive vault items unless you also name them as a beneficiary.

When do beneficiaries find out?

Beneficiaries are invited or notified when a release begins, not when you first add them. They only receive access after the required checks and cooling period finish.

What happens to released access after 90 days?

The access window closes. AevumSecure is designed for handoff, not permanent open access.

Has the security been tested?

Yes. We test and review the security-critical parts of the codebase, especially authentication, encryption, recovery, beneficiary access, and release. We also keep improving the design as new risks and features appear.

Can AevumSecure read my data?

Your vault is encrypted with keys derived from your passkey or password, and every item is protected with a second key held in secure cloud hardware. Both locks are required.

Can my family live in another country?

Yes. You can create your vault anywhere, and beneficiaries can receive access from anywhere. Email is the reliable baseline for reminders and release notices.

What if I forget to check in?

Forgetting once changes nothing. You get repeated reminders, and logging in counts as a check-in. If a release ever starts while you are alive, logging in cancels it.

How do my family actually get access?

When release completes, the people you chose are invited to a secure account. They see only the items assigned to them, and access expires after 90 days.

Do I need a will or a lawyer to use this?

No. You can use the vault on its own. Optional legal tools can help a lawyer reference your vault in a will, but AevumSecure does not replace a will or legal advice.

What if I lose my phone or passkey?

Register more than one passkey and keep your recovery key safe. Recovery deliberately takes 48 hours and notifies you first.