Quick answer

A zero-knowledge vault needs an emergency-access plan that the owner prepares in advance. Identify what a trusted person should be able to recover, keep a verified encrypted backup and its matching Recovery Kit, and store clear instructions through a protected route. Decide separately who may receive those materials and under what circumstances.

Krypt does not provide an automated inheritance service, a trusted-contact invitation, or a server-side backdoor. Its recovery tools can support an owner-arranged plan. Someone who receives usable recovery material and the encrypted data may be able to decrypt it immediately; a written instruction or sealed envelope does not create a cryptographic waiting period.

Recovery capability and permission are different questions

Device loss asks, “Can I get my vault back?” Incapacity or death adds, “Who should act, what should they access, and how will they know what to do?” An encrypted backup may answer the first question while leaving the others unresolved.

Write down the scope: essential household records, selected account instructions, private documents, or other information you intentionally want available. An account password proves technical capability; it does not, by itself, settle a provider's rules or another person's authority to use the account. Coordinate the plan with the relevant provider processes and any legal arrangements appropriate to your situation.

A work vault can contain information owned by an employer. Do not assume it belongs in a personal handover. Use the organization's approved access and continuity process. For personal data, the person you trust to safeguard an envelope may differ from the person who is intended to recover its contents.

Build an account map that does not expose all the secrets

Create a short instruction sheet with the names of important services, the account identifiers needed to find them, where your protected materials are stored, and the provider's official support or legacy process. Keep passwords and Rescue Keys out of an ordinary email or broadly shared document.

Distinguish account access from record access. A beneficiary may need an insurance document or a contact list without needing your entire messaging history. A deliberately limited record collection can be easier to manage than an indiscriminate copy of every account. Review which vault and backup will actually be handed over: a note saying “only use these three items” does not technically restrict a person who can decrypt the whole backup.

Three pieces must remain usable together

A recoverable vault needs more than an instruction sheet
PiecePurposeCheck
Encrypted backupContains the vault data needed for restore.It exists, is sufficiently current, and is accessible without a circular dependency.
Matching Recovery KitContains recovery material for the relevant real vault.It matches that backup's recovery generation and remains protected.
Instructions and release arrangementTell the intended person how to find and use the materials when authorized.The route works if your phone, primary inbox, or memory is unavailable.

Do not put the only backup in a cloud account whose password exists only inside that backup. Do not put the only recovery instructions on the phone that may be unavailable. Store recovery material and the encrypted data separately where practical, while ensuring the intended person can obtain both through your chosen arrangement.

Provider legacy features have their own boundaries

Apple's Legacy Contact lets a chosen person request access to certain Apple Account data after death using the required access key and documentation. Apple expressly excludes iCloud Keychain passwords, passkeys, and payment information. A Legacy Contact designation therefore does not establish recovery of all your credentials or an independently encrypted vault.

Google's Inactive Account Manager can notify chosen contacts or share selected data after a configured period of inactivity. Review exactly which data is included and keep the contacts current. Inactivity is the trigger Google describes; it is not a general immediate-access arrangement for every emergency.

These tools address their providers' data and conditions. They do not automatically supply an independent vault's decryption key. If a provider can deliver a file that happens to be an encrypted backup, the recipient still needs the matching recovery material. Treat cloud-data access and vault decryption as separate checks.

Krypt's answer: recovery tools under the owner's control

Krypt is a local-first zero-knowledge password manager. Secure notes can hold your private account map and handover instructions. Encrypted files can hold selected records. The Recovery Kit supplies user-held recovery material for real vaults, while an encrypted backup supplies the data to restore.

Prepare both. A Recovery Kit is not a copy of the latest vault contents, and a backup without usable recovery material can remain unreadable. Follow the printing and storage guide and the private-backup guide before designing the handover.

Choose a release arrangement you understand. Giving someone both pieces today gives them recovery capability today. Physical custody, a sealed packet, or a documented release process can organize access, but Krypt does not enforce a death certificate, an approval quorum, or a delay. Do not describe this plan as shared-vault administration or automatic emergency access.

Rotation and old copies need a deliberate review

Krypt's Recovery Kit is tied to the relevant backup generation. Backups created before a kit rotation still require the older kit; backups created after rotation require the newer material. Keep a clear association between the backup selected for the plan and its matching kit.

After rotating recovery material, create and verify the new backup and update the handover packet. Decide which older pairs to retain and where they remain. Rotation does not revoke a backup and key that another person already copied, and it does not delete files held by a cloud provider. Do not discard the only working older pair before verifying its replacement.

Test the plan without exposing your live vault

Begin with a harmless rehearsal: use a disposable test vault or test records and follow the normal recovery workflow in a separate, safe environment. Do not overwrite your live vault to test an emergency plan. A sample rehearsal checks the instructions, while a controlled verification of the actual intended backup and matching material checks that the real pair is usable; one is not proof of the other.

During a private real verification, check the correct vault identity, a few representative records, and any files required by the plan. Secure temporary outputs and recovered test copies afterward. The intended person can rehearse finding the instructions without being shown your live secrets prematurely.

Review the plan when life or access changes

  1. Identify the intended person, scope, and release conditions.
  2. Write a short account map and provider-process instructions.
  3. Create an encrypted backup and identify its matching Recovery Kit.
  4. Remove circular dependencies on your unavailable phone or inbox.
  5. Verify the recovery pair without replacing your live vault.
  6. Arrange protected custody and make the consequences of early access clear.
  7. Review after kit rotation, major account changes, device replacement, or a change in the trusted person.

The useful outcome is a plan someone can follow under stress, with the smallest intentional disclosure that meets your needs.

FAQ

Can Krypt automatically give a trusted person access after my death?

No. Krypt provides user-controlled encrypted backups and recovery material, not an automated inheritance or trusted-contact release service. The owner must arrange custody, instructions, and authorized release separately.

Is a printed Recovery Kit enough to recover my vault?

No. Recovery also requires the encrypted vault data in a compatible backup and the recovery material that matches it. The kit is not a copy of the latest vault contents.

Does rotating the Recovery Kit invalidate old backups?

No. Backups created before rotation still require their matching older kit. New backups use the new recovery material. Rotation cannot revoke a backup and key that another person already copied.

Will an Apple Legacy Contact receive my passwords and passkeys?

Apple excludes passwords, passkeys, and payment information stored in iCloud Keychain from Legacy Contact access. Recovery of an independently encrypted Krypt vault also requires its backup and matching user-held recovery material.

Technical references

Use Krypt to protect private records and recovery instructions, then prepare and verify the encrypted backup and Recovery Kit your own emergency plan requires.