PIN Lock
Add a PIN to lock your vault on this device
PIN lock not enabled
Your vault is encrypted on our servers, but a PIN adds a second layer of protection that only you hold. Without it, anyone who can log in to your account can read your vault contents. With a PIN set, only someone with both your account password and your PIN can open the vault.
Tip: Enable OS full-disk encryption
For maximum protection, enable FileVault (macOS) or BitLocker (Windows) on this device. This protects all data — including browser files — if the device is lost or stolen, and works alongside the vault's own encryption.
How your executor accesses the vault
Your executor will need up to two credentials to access the vault online:
Tip: The safest approach is to store credentials with a solicitor or in a sealed envelope alongside your Will, and use the DMS notification message only to say where they are kept. The Executor Pack passphrase (for the offline HTML file) should be stored separately from the login password.
Vault PIN
Locks the vault on this device after login
The PIN is hashed with SHA-256 + a random salt. No plaintext PIN is ever stored on this device.
When the PIN is enabled, all vault data is encrypted at rest using AES-256-GCM (PBKDF2, 310,000 iterations).