Vault

Setting up a vault

Two things in order: a vault key on your account, then an empty folder turned into a vault.

On this page

A vault needs two things, in this order. First a vault key on your account, which is made on your device and is what everything else hangs off. Then an empty folder, which you turn into a vault. You only do the first part once.

1

Make your vault key

Settings, Security, Vault key. A passkey or a passphrase, plus a recovery code you write down.

2

Make an empty folder

Anywhere in Files. A folder that already holds files cannot become a vault.

3

Turn it into a vault

Open the empty folder and press the offer at the top of it.

Step one: your vault key#

  1. 1

    Open Settings, Security

    The section is called Vault key. Press Set up a vault key.

  2. 2

    Choose what holds it

    A passkey means nothing to remember and nothing to type, but not every passkey can hold a vault key and there is no way to tell before asking one. A passphrase works everywhere and has to be at least 12 characters. You can switch between the two later without losing access to any vault.

  3. 3

    Write down the recovery code

    Twenty four characters in six groups of four. This screen is the only place it is ever shown. Tick the box, press Continue, and it is gone.

Nothing you type at this screen is sent to us, then or ever. Your passphrase is stretched into a key in your own browser and used to wrap the private key there. That is also why a wrong passphrase later gives you no hints: it either unwraps the key on your device or it does not.

Step two: turn a folder into a vault#

  1. 1

    Make a new folder in Files

    Or open one you already have that is completely empty, with no files and no subfolders in it.

  2. 2

    Press the offer at the top

    An empty folder shows a line reading "This folder is empty. Make it a vault and everything you put in it is encrypted before it leaves your device."

  3. 3

    Read what it says it gives up

    The panel lists what stays visible to us and which features stop working. Nothing there is a surprise later.

  4. 4

    Press Make it a vault

    The key is minted in your browser at that moment. Your vault key does not even need to be unlocked for this, because the new key is wrapped to your public key.

Adding files#

Inside an unlocked vault, press Add files or drop files onto the panel. Each file is encrypted in your browser first and then uploaded, one after another rather than all at once, so a laptop stays usable while it works. Dropping files onto the page from outside the vault panel is refused on purpose, with a message telling you to use Add files instead.

Encryption is roughly the first third of the progress bar and the upload is the rest. Leave the tab open until it finishes: the encryption is happening in that tab, so closing it stops the upload the way closing any upload does.

PlanStorageLargest single fileUploads per month
Free15 GB500 MB15 GB
Starter150 GB5 GB300 GB
Creator400 GB15 GB800 GB
Pro1 TB25 GB2 TB
Max1.5 TB100 GB3 TB
Business5 TB200 GB10 TB

Vault files are counted like every other file, against the workspace owner's plan. Encryption adds a fraction of a percent to the stored size, so a 4 GB video is still about 4 GB.

Turning a vault back into an ordinary folder#

Only the vault owner can do it, and only while the vault is empty. That is not an arbitrary rule: unmarking a folder that still holds encrypted files would leave files whose bytes nothing can open and whose names nothing can show. Empty it deliberately first, then it is a folder again.

When the offer does not appear#

  • The folder is not empty. One file or one subfolder is enough. Make a new folder instead.
  • You are a viewer in this workspace. Making a vault changes the workspace for everybody in it, so it needs edit access. See Members and roles.
  • You have no vault key yet. Set one up in Settings, Security, and come back to the folder.
  • You are at the top level. The offer appears inside a folder, not on the root of the workspace.
  • Vault is not switched on for your account yet. It is still rolling out.

Related

Still stuck? Email support@nemilab.com and tell us what you were trying to do.