Vault records: passwords, keys, notes, certificates, and files

The browser encrypts each record before it is saved. The list shows each record's name, type, and lifecycle details. The secret value stays masked until someone with access opens it.

Record types
Six secret types
Default view
Values masked
Storage
Encrypted in the browser
Outside lookups
Only when you start them
Illustration of secret records moving into a protected vault rack

Values open only when you ask

With access, you reveal or copy a value only when you choose to, open the site address, or download a permitted file. Opening the site address does not sign you in. Each of these needs an unlocked vault, and your role and vault access decide what you may do.

Password generator and HIBP breach check

The generator defaults to 24 characters, and you can choose from 12 to 64. The value comes from the browser's cryptographic randomness and reaches the vault only when you select Save. The breach check runs only when you start it: the browser sends HIBP only a short prefix of the password's hash. Neither the password nor the full hash is sent.

VirusTotal lookup by file hash

The VirusTotal lookup on the Files screen does not upload the file. It opens the VirusTotal page for the file's SHA-256 digest in a new tab. That sends the digest to a third party. If your policy forbids that, do not use the lookup.

What Quick Recovery leaves out

A Quick Recovery package leaves out file records, record history, audit history, the license, and server settings. A full backup, taken on the Windows server with the Backup Tool, covers more.