Knowledge base: start from the symptom, take one safe step
The knowledge base covers problems during and after installation. Find the symptom you see in the table below and begin with its first safe check.
- Entry point
- Observed symptom
- Method
- One check at a time, in order
- Next step
- Email support@vaultpilot.io

When the article does not solve it
Collect the redacted details the article asks for and continue through private correspondence with support@vaultpilot.io. Inconclusive first checks are no reason to widen what you send. These details are safe to send.
FIND BY SYMPTOM
What you see, and where to start
Run the first check before you change anything. If the article does not solve the problem, send support only redacted details.
| Area | Symptom | First safe check | Article |
|---|---|---|---|
| Installer | The VaultPilot MSI does not complete, or the service does not start after installation. | Confirm the MSI was launched as Administrator. | MSI installation fails |
| Server settings | Server System settings were saved, but browser access, HTTPS, notifications, logs or the service restart state still need review. | Reopen VaultPilot from one canonical URL. | Server settings need a restart or maintenance review |
| Certificate | Users see a browser warning after HTTPS is enabled. | Confirm that the public host name in Server settings is the DNS name or IP users actually open. | HTTPS certificate warning |
| Session | Right after login, VaultPilot keeps rejecting the session and pages fail to load or ask you to sign in again. | Log out, close stale tabs and open VaultPilot from one canonical URL. | Repeated 401 or 403 errors after sign-in |
| Extension | The extension is installed, but the VaultPilot panel stays pending, does not show the device, or stops syncing after pairing once. | Confirm the server address in the extension exactly matches the VaultPilot host, port and scheme. | Extension pairing remains pending |
| Sharing | The Offline Share Decrypter rejects the package, reports a passphrase problem, or opens without the expected records. | Open Sharing and confirm the package was created from the intended records only. | External share package fails to open |
| Discovery | Discovery reports a secret exposure signal, import is disabled, or it is unclear whether a finding should become a vault record. | Confirm the scan policy shows an approved private network, Windows folder preset, local path or SMB path. | Reviewing Discovery findings |
| Backup | A backup import fails, returns an archive error, rejects an oversized upload, or succeeds and closes active sessions. | Identify the backup type first: Quick Recovery, full Backup Tool backup or maintenance backup. | Backup import fails or closes sessions |
| Update | The update stays around 76 percent and the browser may lose contact with the server. | Leave the update job detail visible and wait for the service restart window to finish before retrying. | Update stays around 76 percent |
| Directory | The VaultPilot DC Agent Service cannot install, connect, sync or recover. | Confirm the VaultPilot URL is reachable from the domain-side machine. | DC Agent service troubleshooting |
| License | Login and viewing work, but writes, user changes, sharing, pairing, discovery import or update installation are blocked. | Open License and use the topbar help icon to confirm the expected state. | License read-only state |
| Audit | The Audit Log screen reports a partial chain, an inconsistent hash sequence, or missing rows after restore. | Capture the active filters, date range and visible chain state before changing anything. | Audit chain is partial or inconsistent |
| Redaction | You need to send screenshots or logs to support, but they contain tenant, host, user, secret or license data. | Replace token, host, user, path and secret values with <REDACTED> before sending. | Redacting support evidence |
| API | An integration API client gets 401, a scope-denied response, or an empty encrypted snapshot. | Confirm the client calls the VaultPilot server it was created on, at that server's HTTPS address. | Integration API client gets 401, scope denied, or no data |
Limits to know
- A knowledge base article is not permission for unrelated cleanup, destructive repair, or unsupported configuration changes.
- A similar symptom can have a different cause, so record your observations anyway.
- Databases, backups, certificates, keys, token values, screenshots with real vault data, and raw logs with secrets stay out of every support message.
Check step by step
- 01
Record the exact message, screen, version, time, and last known good state.
- 02
Open the article that matches the affected area.
- 03
Run the checks in order and stop at any trust or integrity mismatch.
- 04
If it is still broken, prepare the listed redacted details and write to support@vaultpilot.io.
Read more in the guides: Troubleshooting guide, Support evidence pack