টাকা, সম্পত্তি ও মূল্যবান জিনিসগুরুত্বপূর্ণ নথি ও উইলচিকিৎসা সংক্রান্ত ইচ্ছা ও জরুরি তথ্যস্মৃতি, গল্প ও ভয়েস নোটসম্পর্ক ও বিশ্বস্ত মানুষ
সুরক্ষা ও গোপনীয়তাSoult কিভাবে কাজ করেএক্সিকিউটর ও হ্যান্ডওভার ফ্লোআইনি বৈধতাLegal Help Centreসিকিউরিটি হোয়াইটপেপারব্লগ ও লাইফ গাইডহেল্প সেন্টারSoult সম্পর্কে
প্রাইসিং
কর্পোরেট এমপ্লয়ি ওয়েলনেসচ্যানেল পার্টনার্স
আমার অ্যাকাউন্টআজই সুরক্ষা শুরু করুন
← Back to Blog
securityprivacyencryptionpassword-keeperdigital-legacy

A Vault Inside Your Vault: How Soult Protects the Passwords Even We Cannot Read

Sanketh Kandlikar·5 August 2026
📖

Every vault built for families has a contradiction at its centre.

The whole point of Soult is that the people you love can get in. If you are gone, or in a hospital bed, or simply cannot remember where anything is, your family should not be locked out of your own life. That means recovery has to work. It means we have to be able to help.

But some things should not work that way. Your bank login. Your email password. The recovery phrase for a crypto wallet. For those, the honest answer is not "we keep them very safe" — it is that nobody should be able to open them but you. Not your executor before their time. Not us. Not anyone holding a court order.

Most products pick a side. Password managers choose absolute secrecy and tell you that if you forget your master password, everything is gone. Cloud storage chooses recoverability and quietly keeps a key. Both are defensible. Neither is right for a life vault, because a life vault needs to do both.

So we built a vault inside your vault.

Two levels, and you choose per entry

The Password Keeper has two levels.

Standard entries are the everyday ones — the Wi-Fi password, the streaming login, the shared account nobody would lose sleep over. They unlock with your app MPIN. They are encrypted, they are protected by our infrastructure, and if you lose your phone or forget your credentials, we can help you get back in. That help is a feature, not a weakness. It is why your family is not locked out.

Advanced entries work on completely different rules. You set a separate vault password, and that password never leaves your phone. Your bank login is encrypted on your device, before it travels anywhere. What reaches our servers is a locked box, and we do not hold the key. There is no Soult decrypt button, no support override, no senior engineer who can be persuaded. If you lose the vault password and its backup, that entry is gone permanently.

You decide which entries deserve which level. Most of your Password Keeper probably does not need Advanced. The handful that do, genuinely do.

The part that usually surprises people

Here is where our design differs from most encryption you have used.

Normally, turning on end-to-end encryption means you have to type your master password every time you touch anything — to read and to write. That gets tiring fast, and tiring is how good security ends up switched off.

With Soult, adding an Advanced entry needs no password at all. Only reading one does.

The nearest everyday comparison is a letterbox. Anyone can post a letter through the slot — it takes no key. Only the person holding the key can open the box and read what is inside. Your phone holds a public "slot" that can seal new entries, and a private key that can open them. The private key is what your vault password unlocks.

So the day-to-day feel is ordinary. Save a new bank password, and it is sealed instantly, no prompt. The vault password appears only in the moment you actually want to look at something — which is rare, and which is exactly when a prompt makes sense.

What we actually store

We think you should be able to check this rather than take our word for it, so plainly:

  • Your public key, which is not a secret and cannot open anything
  • Your private key, locked with a key derived from your vault password
  • Each Advanced entry as ciphertext, plus the technical scraps needed to unlock it with the right key

That is the whole list. Your vault password is not in it. It is never transmitted, never stored, and never seen by us — not as text, not as a hash, not in a log.

If someone stole our entire database tomorrow, your Advanced entries would be unreadable noise to them. So would they be to us.

The full specification — the algorithms, the key derivation parameters, the exact structure — is published in our security whitepaper. We would rather be checked than believed.

Recovery, and the one thing we cannot undo

When you switch on Advanced, we generate a 12-word recovery phrase and show it to you once. Write it down. Keep it somewhere real — a diary, a locker, a sealed envelope with your will.

That phrase is a second, independent way to unlock the same private key. It never reaches our servers either. If you forget your vault password, the phrase gets you back in. If you lose both, nothing can be done. Not by you, not by us.

We know how that sounds. It is the trade-off, stated honestly: the only way for us to be able to rescue you is for us to hold a key — and the moment we hold a key, so does anyone who can compel us to use it. You cannot have both. We would rather tell you that clearly than discover it together on your worst day.

One deliberate detail: your app MPIN is not part of this encryption. It would have been easy to fold it in and sound more secure. But people change their MPIN, and a changed MPIN would have silently destroyed every Advanced entry, with no warning and no way back. So the MPIN guards the door, and the vault password guards the box, and changing one can never break the other.

Why this matters beyond passwords

There is a question every Indian family should be asking of anything that holds their documents: what happens when someone with authority asks?

For most of your vault, our answer is the ordinary lawful one — we follow due process, we disclose only what we are legally required to disclose, through a controlled and audited path. We are not above the law and we would not pretend otherwise.

For Advanced entries, the answer is different, and it is different because of mathematics rather than policy. We can be compelled to hand over what we hold. What we hold is a locked box. We cannot be compelled to produce a key that does not exist on our side.

That is the difference between a company promising it will not look, and a company that has arranged things so it cannot.

Where to start

If you have not turned it on: open the Password Keeper, switch on Advanced, and move three entries into it. Your primary bank login. Your main email password. One more that you would hate to see in someone else's hands.

Then write the twelve words down and put them somewhere your family would eventually find, but a stranger would not.

That is ten minutes of work, and it is the difference between trusting us and not having to.

Ready to secure your family's future?

Start your free Life Vault today. No credit card required.

Start Free
Share:LinkedInTwitterFacebookCopy Link
iOS ও Android-এ উপলব্ধ

আপনার ডিজিটাল জীবন ও তার পরের জীবন,
সুরক্ষিত।

প্রতিদিনের জন্য দরকারি — আপনার সম্পত্তি, স্মৃতি এবং জরুরি কাগজপত্র গুছিয়ে রাখুন একটি প্রাইভেট ভল্টে। সবকিছু আপনার পরিবারের কাছে ঠিক যেমন আপনি চান, যখন সময় আসবে, পৌঁছে দেওয়ার জন্য তৈরি।

5.0/5 রেটিং — সব রিভিউ।
অ্যাপ স্টোরে 18 · গুগল প্লে-তে 21 · মোট 39
আপনার ভল্ট প্রতিটি স্তরে এনক্রিপ্ট করা আছে — AES-256 অ্যাট রেস্ট, TLS ইন ট্রানজিট, এবং শুধুমাত্র আপনার দ্বারাই আনলক করা যায়।
ISO/IEC27001সার্টিফাইডISO 27001 ↓তথ্য সুরক্ষাISO9001সার্টিফাইডISO 9001 ↓গুণমান ব্যবস্থাপনা
AES-256ট্রানজিট ও অ্যাট রেস্টে এনক্রিপশন
AWSAWSনিরাপদ ক্লাউড হোস্টিং
Secured on AWS architecture