Frequently asked questions about VaultPilot

Short answers to the questions evaluators ask first.

Is the master password sent to the server?

No. VaultPilot uses the master password in the browser; the plaintext master password is not sent to the server.

Read more: Security and trust model

Where does VaultPilot keep its data?

On your own server, under C:\ProgramData\VaultPilot. Vault values are encrypted in the browser, so the server stores them only in encrypted form.

Read more: Windows Server installation

How is an update verified if the MSI is unsigned?

The VaultPilot-managed update path checks the Ed25519-signed update manifest, the allowed release host, the exact SHA-256 hash of the file, and its size. The published v3.0.3 MSI is unsigned, so no claim is made about a signing certificate, and Windows may show a reputation warning before installation. Trust comes from the manifest signature and the file hash.

Read more: Release asset verification

Can files be shared?

Yes. VaultPilot can include selected file records in external share packages. Set an expiry date and a maximum number of opens when you share.

Read more: Sharing and offline decrypter

Not answered here?

The documentation covers installation, updates, backup and recovery screen by screen, and the knowledge base is sorted by symptom. For anything else, write to support@vaultpilot.io.

Open the documentation