The short version: IvorySafe uses end-to-end encryption. The information you put in your vault is scrambled before it ever leaves your device, and the scrambled version is the only thing IvorySafe's servers ever see. The longer version is worth understanding, because the specifics of how this works are what separate real privacy from the marketing version of privacy.

What "end-to-end encrypted" means

End-to-end encryption is a phrase used so often in tech marketing that it has lost most of its meaning. The actual technical definition is simple: information is encrypted on your device before it's sent anywhere, and only people who have the key can ever decrypt it. The company in the middle, hosting the service, isn't one of those people.

A useful analogy is sending a letter in a sealed lockbox instead of an envelope. With a regular envelope, the post office can't easily read it, but if they wanted to, they could. With a sealed lockbox where only you and the recipient have a key, the post office can carry it from one place to another, but no one inside the post office can open it. End-to-end encryption is the digital version of the lockbox.

In IvorySafe specifically, this means everything in your vault, meaning every account number, every password, every doctor's name, every document, every detail you've entered, is encrypted on your device using a key derived from your password. That encrypted blob is what gets sent to IvorySafe's servers. The servers store it. They never store the key. They never see the contents in plain text. They couldn't read your vault even if they wanted to.

What this protects against, and what it doesn't

Being clear about the scope of any security claim is what makes the claim credible. End-to-end encryption is a meaningful protection, but no single technology is a complete defense against every threat. Here is what's true:

What end-to-end encryption protects against

  • A breach of IvorySafe's servers. If a bad actor ever gained access to IvorySafe's database, they would find a vault of encrypted blobs with no keys. The data would be unreadable. This is the single most common kind of breach in the news every week, and it's the one this architecture defeats.
  • An employee at IvorySafe trying to look at your data. Not even IvorySafe staff can read your vault. There is no internal admin tool that bypasses the encryption, because the company doesn't have your key.
  • A subpoena or government request for your data. If IvorySafe is ever legally required to hand over what it has, what it can hand over is the encrypted blob. Without your password, that blob is useless.
  • Network interception. Even if someone managed to capture the data in transit between your device and IvorySafe's servers, what they would capture is the already-encrypted version.

What end-to-end encryption does not protect against

  • Someone gaining access to your unlocked device. If a person picks up your phone or laptop while you're logged into IvorySafe, they can see what's in your vault on the screen. This is why device passcodes, biometric locks, and session timeouts still matter.
  • A weak or reused password. The encryption is only as strong as the password protecting it. A six-character password that you also use for your email account is a much weaker defense than a long, unique passphrase used nowhere else.
  • Phishing. If someone tricks you into typing your IvorySafe password into a fake website, no amount of encryption helps. Always verify you're at the real IvorySafe site before logging in.
  • Sharing your password. Encryption assumes your password stays yours. Anyone who has it has the same access you do.

None of these are flaws in the encryption itself. They are the boundaries of what any technical security can do. The point of being transparent about them is so you understand where the protection ends and where your own habits become the rest of the defense.

The trade-off we accepted: there is no password recovery

The biggest practical consequence of true end-to-end encryption is the one that catches users off guard if no one explains it up front. Because IvorySafe doesn't have your encryption key, IvorySafe also can't reset your vault for you if you forget your password.

This is a hard constraint. Every other major service you use, whether your email, your bank, or your phone, has some way to verify your identity and let you back in. IvorySafe deliberately does not, for the vault data itself. If you forget your master password, the encrypted blob on the server is unreadable, even to us, even with the most heartfelt support ticket.

This is a real cost, and it's the price of a security model with no back door. Any company that promises both perfect privacy and full password recovery is promising something that isn't possible. They either have your key (and can therefore read your data, contrary to whatever the marketing says) or they have a master key that can decrypt any user's vault (which is the same problem). We chose the version that protects you.

What this means practically: pick a strong master password, and store it somewhere safe and durable. A piece of paper in a fireproof home safe is a perfectly reasonable place. So is a dedicated, encrypted password manager like 1Password or Bitwarden, both of which use the same kind of end-to-end encryption IvorySafe does. The goal is to make sure you can always get to it, and that no one else can.

How emergency contacts work without breaking the encryption

If IvorySafe can't decrypt your vault, and your emergency contacts need to be able to see it in an emergency, how does that work?

The answer is that emergency contacts are part of the encryption design from the beginning, not an exception bolted on later. When you designate an emergency contact, IvorySafe creates a specially protected copy of the access key that only your contact's own password can unlock. That protected copy sits in your vault, dormant, until two conditions are met: an access request is activated, and the waiting period you chose for that contact expires.

Once both conditions are met, your emergency contact can use their own password to unlock the access key and see what's in your vault. IvorySafe never holds the unlocked key, even during an emergency. The encryption boundary is preserved end to end, even at the moment access activates.

This design also depends on your emergency contacts remembering their own passwords. If you designate someone as a contact and they later forget the password they used to set up their IvorySafe account, they won't be able to decrypt your vault when the time comes. Tell your contacts to treat the password they pick with the same care you treat yours.

Why we built it this way

Most companies that handle sensitive data don't use end-to-end encryption. The reason is simple: it's harder to build, it's harder to support, and it means you can't offer the kind of "we'll just reset that for you" support that most users expect from most services.

For something like family emergency information, those trade-offs are worth it. The vault is meant to hold the entire blueprint of your household: bank accounts, insurance policies, medical history, passwords, the location of important documents, who your family should call first. If a company were able to read any of that on the inside, you would be putting an enormous amount of trust in their employees, their internal controls, their legal team, and the strength of their corporate infrastructure. With end-to-end encryption, the math itself is the protection. The company can't betray your trust because the company can't see what's in the vault.

That's the right architecture for the kind of information IvorySafe is designed to hold. It's the architecture used by Signal, Apple's iCloud Advanced Data Protection, 1Password, and other services that take privacy seriously. The constraints are real, but the protection is also real.

What this means for you

A short list of practical takeaways:

  • Pick a strong master password and write it down somewhere safe. A long passphrase you don't use anywhere else, written on paper in a place only you can access. Treat it like the key to a safe deposit box.
  • Don't reuse it. The strength of your encryption depends on the master password being unique to IvorySafe.
  • Keep your device secure. A locked phone with a biometric or strong passcode is the other half of the system.
  • Tell your emergency contacts the same. Their password matters too, because it's the key they'll use if they ever need to step in.

How to get started

Where to begin depends on whether you already have a vault set up.

If you haven't started yet

Start a free trial of IvorySafe and walk through the initial assessment. It takes about 5 to 10 minutes, and the very first thing you'll be asked to do is set your master password. Pick a strong one, write it down safely, and treat it as the key to everything else.

Start your free IvorySafe trial →

If you're already signed up

A few practical things to do this week:

  1. Confirm your master password is stored somewhere durable. If you couldn't recover it from memory right now, you need a backup. Paper in a fireproof home safe is fine. A dedicated encrypted password manager like 1Password or Bitwarden is fine. A sticky note on the side of your monitor is not.
  2. Check that your master password isn't used anywhere else. Unique passwords are the difference between one compromise and a cascading one. If your IvorySafe password is also your email password, change one of them.
  3. Tell your emergency contacts about their own password. When they accept the role, they pick a password that becomes the key to your vault in an emergency. Make sure they understand that, and that they write theirs down too.

Strong encryption is what makes IvorySafe trustworthy enough to hold the kind of information it holds. Strong personal habits are what make that trust hold up over time. The first one is on us. The second one is on you.

Have a question we didn't cover?

Our support team is small, human, and happy to help you think through what to put in your vault.

Email support

Or copy and paste: support@ivorysafe.com