You can use your records now.
This browser is approved and the household is open.
Vault document contents are encrypted in your browser before upload. The server can read the title, date, type, status, and relationships you enter so it can organize the record.
The server stores encrypted file contents. It can read the information you enter to organize them.
Encrypted in the browser before upload. The server stores encrypted bytes, not readable document contents.
The server can read the title, date, document type, status, and related people, accounts, property, or year.
The server stores encrypted key envelopes but does not receive plaintext vault keys, file keys, or your recovery code.
Your message and any screenshot you choose to attach are readable by RecordWarden, the email delivery provider, and authorized support staff. They are not encrypted with your vault key, so review and redact the screenshot before sending it.
Document bodies are Encrypted in the browser with AES-256-GCM before upload. Each document has a unique file key, wrapped by the household vault key.
Plaintext vault keys, file keys, and recovery secrets stay out of the server. The server stores encrypted key envelopes and the cryptographic information needed to deliver them.
RecordWarden’s servers store the specific details needed to organize your records, such as the title, date, document type, status, and validated details about who or what the record belongs to.
Plaintext OCR, full-text indexes, embeddings, arbitrary extraction dumps, folder paths, and user-managed tags are not stored by the server.
Vault encryption does not cover support communications. A feedback screenshot is optional and is sent only after you capture, review, and submit it.
Signing in verifies your account. A browser also needs access to the vault keys before it can open file contents.
This browser is approved and the household is open.
This browser worked before, but needs to be unlocked again.
Use your recovery code or approval from a browser that already works.
These limits are part of RecordWarden’s security model.
If every approved browser and the recovery code are lost, no one—including RecordWarden support—can reopen the household.
Removing someone stops future access through RecordWarden. It cannot take back information or keys they already saved.
A new recovery code is shown when it is created and cannot later be retrieved.
A web application cannot protect against a malicious replacement of its own JavaScript. RecordWarden assumes the reviewed browser application and HTTPS update pathremain trustworthy.
Removing a member blocks future service access but cannot recall plaintext, envelopes, or keys already saved, and it does not provide forward secrecy.
Join the invitation list, or sign in if you already have an account.