🔒 Your Share of the Security

Secure Passwords

The strongest encryption doesn't help much if the password in front of it is weak or reused. A large part of your own security is up to you – here's what actually matters.

How to lower your personal data-leak risk

Most compromised accounts aren't broken through cracked encryption, but through weak or reused passwords that leaked at a completely different provider.

🧩

A unique password for every service

When a password leaks at one provider, attackers automatically try it against hundreds of other services (credential stuffing). A reused password turns someone else's data breach into your own.

📏

Length beats complexity

A long passphrase made of several random words is easier for you to remember and harder for a computer to guess than "Summer2024!". At least 16 characters is a good rule of thumb.

🗝️

A password manager instead of your memory

Nobody can remember dozens of unique, long passwords – and you don't need to. A password manager generates and stores them encrypted; you only need to remember one vault password for it.

📱

Two-factor authentication wherever possible

A second factor – an authenticator app or a passkey – protects your account even if a password does end up in the wrong hands despite every precaution.

🕵️

Check regularly for known data breaches

Services like "Have I Been Pwned" show whether your email address has appeared in a known data breach. If it has, change the affected password right away – everywhere you reused it.

🚫

No passwords in plain-text notes

A notes app, a text file, or a sticky note on the monitor are not a safe place to keep them. That's exactly what password managers – and, for your digital legacy, finilog – are for.

Why we use three different passwords

Login password, vault password, and Recovery Kit look like unnecessary complexity at first glance. Each actually protects against a different risk – and the separation itself is a security feature.

👤

Login Password

Signs you in to finilog just like with any other online service. It opens your account, but not your vault – it is never used for encryption or decryption.

🔑

Vault Password

Never leaves your device. It is used locally to derive the key that encrypts and decrypts your legacy entries. We never store it, and consequently we cannot reset it either.

📜

Recovery Kit

A one-time printed code for the worst case: if you forget your vault password, this is the only way back into your vault. It can optionally be bound to a passkey as well.

The reason for the separation: a compromised login password still doesn't open a vault, a vault password on your device is never exposed to a server breach in the first place, and the Recovery Kit works independently of both – a deliberately offline-only lifeline. A single shared password for everything would be easier to remember, but any one weakness would instantly become a weakness for everything else.

What if I'm named someone's beneficiary myself?

As soon as you're listed as someone's beneficiary, you automatically get your own keypair, used to encrypt inherited data specifically for you later on. Its private half can be unlocked – just like above – three independent ways: your login password, a passkey, or your own Recovery Kit. Your login password takes on a second job here.

This is intentional, and less risky than it sounds: this key doesn't unlock anything at all unless an inheritance case has actually been triggered and approved by us – only then does inherited data become decryptable in the first place. Your login password really only protects something in that one specific moment, not before. If you change your login password, this protection is automatically updated with the new one.

How the vault password is actually used

From typing your password to an encrypted entry – the technical details of our zero-knowledge architecture.

Understand zero knowledge →

Change your password or manage your Recovery Kit

Update your login password, set up two-factor authentication, or bind your Recovery Kit to a passkey.

Go to settings →

Start with a strong vault password

A unique, long vault password is the single most important step to actually protecting your digital legacy.

Start for free