Security

What RecordWarden protects—and what it can see.

Vault document contents are encrypted in your browser before upload. The server can read the title, date, type, status, and relationships you enter so it can organize the record.

Server-visible data

File contents and record details are handled differently

The server stores encrypted file contents. It can read the information you enter to organize them.

Vault document contents

Encrypted in the browser before upload. The server stores encrypted bytes, not readable document contents.

Record details

The server can read the title, date, document type, status, and related people, accounts, property, or year.

Keys and recovery code

The server stores encrypted key envelopes but does not receive plaintext vault keys, file keys, or your recovery code.

Feedback you choose to send

Your message and any screenshot you choose to attach are readable by RecordWarden, the email delivery provider, and authorized support staff. They are not encrypted with your vault key, so review and redact the screenshot before sending it.

Technical details for security reviewers

Document bodies are Encrypted in the browser with AES-256-GCM before upload. Each document has a unique file key, wrapped by the household vault key.

Plaintext vault keys, file keys, and recovery secrets stay out of the server. The server stores encrypted key envelopes and the cryptographic information needed to deliver them.

RecordWarden’s servers store the specific details needed to organize your records, such as the title, date, document type, status, and validated details about who or what the record belongs to.

Plaintext OCR, full-text indexes, embeddings, arbitrary extraction dumps, folder paths, and user-managed tags are not stored by the server.

Vault encryption does not cover support communications. A feedback screenshot is optional and is sent only after you capture, review, and submit it.

Browser access

Signing in and unlocking files are separate

Signing in verifies your account. A browser also needs access to the vault keys before it can open file contents.

Approved and open

You can use your records now.

This browser is approved and the household is open.

Approved but locked

Open the household again.

This browser worked before, but needs to be unlocked again.

New browser

Approve this browser first.

Use your recovery code or approval from a browser that already works.

Limits and responsibilities

Keep the recovery code and understand shared access

These limits are part of RecordWarden’s security model.

Keep your recovery code

If every approved browser and the recovery code are lost, no one—including RecordWarden support—can reopen the household.

Understand shared access

Removing someone stops future access through RecordWarden. It cannot take back information or keys they already saved.

Save a replacement code immediately

A new recovery code is shown when it is created and cannot later be retrieved.

Security boundary details for reviewers

A web application cannot protect against a malicious replacement of its own JavaScript. RecordWarden assumes the reviewed browser application and HTTPS update pathremain trustworthy.

Removing a member blocks future service access but cannot recall plaintext, envelopes, or keys already saved, and it does not provide forward secrecy.

Request access to RecordWarden.

Join the invitation list, or sign in if you already have an account.