Why this exists
Crypto doesn't get inherited.
It just stops.
A bank account has a next of kin. A wallet has a seed phrase and nothing else. When the person who memorised it is gone, so is the money.
Not stolen — stranded. Chainalysis estimates that 2.8 to 3.8 million coins have sat untouched since Bitcoin's early years. They still exist; nobody alive can move them.
There is no support line and no password reset. If the phrase is gone, the wallet is gone.
A safe, a drawer, a deposit box. It survives fire and flood right up until it doesn't — and your family still has to find it.
Loss estimate: Chainalysis — 2.78–3.79M BTC dormant since Bitcoin's early years. A cumulative total since 2009, not a yearly figure, and an estimate rather than a count.
How It Works
Three steps to protect your digital legacy.
No third-party custody. No plaintext stored. Your secrets stay yours — even after you're gone.
The Dead Man's Switch
It should be hard to trigger by accident.
This is the mechanism everything else depends on, so here is exactly how it behaves — including when it doesn't.
What counts as a missed check-in?
You choose your own check-in interval. Nothing is "missed" until that full interval passes with no check-in from you — opening the app, tapping the emailed link, or replying to the Telegram bot all count. A single check-in resets the clock completely.
What stops a false trigger?
Two layers. First, you get five escalating reminders before the interval even ends — the first after a day of inactivity, then at roughly half, three-quarters, ninety and ninety-seven percent of your interval. Second, the interval expiring does not release anything: it starts a grace period of 7 days, or 100 days on Sentinel and Dynasty. You get an alert four days before the trigger and a final warning one day before.
What if I'm in hospital, travelling, or off-grid?
Set your interval to match how you actually live, not how you plan to. On the annual and lifetime plans the grace period alone is 100 days on top of your interval — an extended absence will not fire the switch. If you know you will be unreachable, lengthen your interval before you go.
What actually happens when it fires?
We combine the two shards we hold and deliver them to the heir you named, along with the recovery steps. Your owner shard is never involved. Nothing is released early, and nothing is released to anyone other than the heir you confirmed in advance.
What if the switch itself fails?
Check-in monitoring runs on our servers, and the deadline is measured purely as time since your last check-in. An outage does not pause that clock — if we are down while your window elapses, the release can fire when we come back, even though you were alive and simply unable to check in. We think release should require positive evidence that a deadline was genuinely missed, not merely the absence of a check-in, and we are changing it to work that way. Until then, longer check-in intervals reduce the exposure.
Before you trust us with anything
Why your secrets stay yours.
You shouldn't need to understand cryptography to trust us with something this important. Here is what it means in plain English — and where to check each promise for yourself.
Unreadable before it leaves your device
Your passwords and recovery phrases are encrypted on your own device, before anything is stored or sent. What reaches our servers is unreadable text — never the secrets themselves.
See how encryption works →We hold the timer, not your passwords
Your key is split into three pieces. We keep two of them encrypted, and only bring them together if your check-ins stop. We publish exactly what we hold — and what could still go wrong.
See what we don't protect against →It still works if we disappear
The code that opens a vault is public and permanently archived, so decrypting never depends on our servers, our app, or an active subscription. It does depend on you holding two of the three shards — export yours, or a shutdown strands the vault.
View the recovery guarantee →Real people behind VaultPass
Built in the open by a named founder, Suresh Kumar Ramar, with a published internal security review and a standing invitation for researchers to find our flaws.
Meet the people behind it →Rather not take our word for any of it? Good — neither would we.
Instead of testimonials
We're early. Judge the code, not the quotes.
VaultPass is a young product, so we have no customer stories worth printing yet. Here is what you can verify without trusting us.
Under the hood
The detail, if you want it.
Everything above, stated precisely — the algorithms, the key-splitting scheme, our audit status, and a snippet you can paste into your own browser console to check the encryption yourself.
Why not just 1Password or Bitwarden?
They're great password managers.
Inheritance is an afterthought.
Both encrypt on your device — and we respect them. But neither is built for crypto succession. That's the whole point of VaultPass.
| Feature | 1Password / Bitwarden | VaultPass |
|---|---|---|
| Client-side encryption | Yes | Yes |
| Purpose-built for crypto seed phrases | General credentials | Yes |
| Inheritance model | Bolt-on emergency access | Dead man's switch + grace period |
| How the heir gets your key | Access to your whole vault | Shamir 2-of-3 — released only when the switch fires |
| Recovery if the company shuts down | Vault tied to their service | Open-source recovery — decrypt without us |
The unique advantage:VaultPass is built ground-up for crypto succession — a dead man's switch, Shamir-sharded keys, and recovery that survives even us.
Pricing
You pay us, so nobody else does.
Subscription only. We don't take a cut of your assets, we don't hold your funds, and there is nothing to sell on — the vault contents are unreadable to us.
Monthly Vigil
$39/month
Cancel anytime.
Sentinel
$299/year
$24.92/month, billed once a year.
Dynasty
$999 once
Founding price — rises JANUARY 2027.