Create your vault

Your vault is encrypted in your browser before it reaches our servers. Set a strong passphrase — we cannot recover it if lost.

Name is required.
Valid email required.
Passphrase must be at least 10 characters.
Passphrases do not match.

Your passphrase is your vault key — and we never see it.
Holdfast encrypts your vault in your browser using AES-256 before it ever reaches us. We cannot read it, recover it, or reset it. Treat your passphrase like a master key: write it down somewhere physical (a password manager, a safe, a sealed envelope), not in a draft email or a notes app you might lose access to.

There is no “forgot passphrase” recovery. If you ever lose it — or believe it has been compromised — the only path forward is to export your vault, sign up a new account with a fresh passphrase, and import. (Personal plan and above.) Pick a multi-word phrase like river-clock-bright-41 and commit to remembering it.

Already set up a vault? Sign in here

Sign in

Sign in to access your vault.

Lost access to your email? Forgot password?
or
No account yet? Create one here

Create account

Set up your account. You'll create your vault passphrase in the next step.

Name is required.
Valid email required.
Password must be at least 8 characters.
Passwords do not match.
I agree to the Terms of Service and Privacy Policy
You must agree to the Terms of Service and Privacy Policy.
Already have an account? Sign in here

Welcome back

Enter your vault passphrase to decrypt and load your vault.

Incorrect passphrase. Please try again.
No vault yet? Create one here
Not your account? Sign out & clear session

Reset password

Enter your account email and we'll send you a reset link.

Lost access to your email? Recover your account

Set new password

Choose a new password for your account.

Active
Next check-in:
Unsaved changes

Your vault

Recipients

The people who will receive access to your vault if you stop checking in. Each recipient gets their own secure link.

Settings

Account
Your profile
This name appears on your vault when it's delivered to recipients.
Passphrase hint
Leave an optional hint to help your recipients remember the passphrase. This is not encrypted — it will be visible in the delivery email and on the vault open page.
0/200
Check-ins
Check-in schedule
How often would you like to confirm you're okay? You'll receive an email with a one-click confirmation link.
Check in now
Confirm you're okay and reset your check-in timer. Useful before travelling or going somewhere without reliable email access.
Pause check-ins
Going on holiday or know you'll be unreachable? Pause your check-in schedule. Your vault stays safe and no escalation emails will be sent while paused. Resume when you're back.
Vault status
StatusActive
Next check-in due
Last check-inNever
Missed check-ins0
Check-in streak
Check-in frequencyMonthly
Vault & Data
Export vault
Download a decrypted, human-readable copy of your vault as a PDF. Use it as a physical backup — print it, seal it, and store it somewhere safe.
Vault size — MB of 3.5 MB
Plan & Billing
Plan & Billing
You're on the Free plan — up to 5 entries and 1 recipient. Upgrade for unlimited entries, more recipients, and file attachments.
Personal — £5/mo · unlimited entries · 3 recipients
Family — £9/mo · 2 vaults · 5 recipients each
Advanced
Sign out
Removes your vault from this device. Your encrypted vault remains on our servers — sign in again with your passphrase to access it.
○ GDPR · Right to Erasure
Danger zone
Permanently delete your vault and all associated data — entries, recipients, check-in history, and your account. This cannot be undone. Your Stripe subscription (if active) will be cancelled immediately.
Under GDPR Article 17, you have the right to complete erasure of your personal data. We honour it here, in full, with no retention.
A Nexus Company · holdfast-co.uk
Confidential
This document contains the decrypted contents of a Holdfast vault. It was produced at the owner's request. Store securely — do not leave unattended.
holdfast-co.uk
HOLDFAST
A Nexus Company

Digital Estate Addendum

Supplementary estate document — to be filed alongside the last will and testament

Declaration

Signed
Date
Witness (optional)
Disclaimer: This addendum is an informational document. It does not constitute a legal will, codicil, or binding legal instrument. Nexus-Sectech Ltd does not provide legal advice. Please consult your solicitor or lawyer for guidance on estate planning and the legal standing of this document.
Help & Support
No — not immediately. There is a grace period after a missed check-in before escalation emails begin. Log in and use the "Check in now" button in Settings to reset your timer immediately.
This usually happens when your browser's local storage has been cleared. Your vault is safely stored on our servers. Sign in on your usual browser and device and your entries will reappear.
This occasionally happens if the payment confirmation is briefly delayed. Wait 10 minutes and sign out then back in. If your plan still shows as Free after that, contact us with your account email and payment confirmation.
Recipient access links are valid for 30 days from delivery. If the link has expired, contact us — we can issue a new delivery token manually.
Recipients have 30 days of access via their personal link. On day 23 we email each recipient a 7-day warning so they can save anything they need. On day 30, the entire vault is permanently purged:
  • Encrypted vault contents and passphrase hint — wiped
  • All attachments and video files — removed from storage
  • Recipient records and access tokens — deleted
  • Your account row — anonymised (name/email replaced)
  • Stripe subscription — cancelled if still active

After this point the vault cannot be recovered or re-delivered, even by Holdfast staff. This is intentional — sensitive material is never retained indefinitely.

Settings → Account → Delete vault & account. For safety, deletion takes two steps — confirm in the app, then enter a 6-digit code we email you. After that, your vault enters a 7-day cooling-off period during which you can cancel from the banner at the top of your vault, or via the link in the confirmation email. After 7 days, the deletion is permanent and cannot be reversed.
Because Holdfast never sees your passphrase, we cannot reset it. The safest path is to migrate your vault under a new passphrase:
  1. Export your current vault from Settings → Export vault. The export file is encrypted with your current passphrase.
  2. For any video messages, open each video entry, play the video, then use your browser's video controls (right-click → Save video as) to save a local copy. Videos are stored outside the vault blob and are not included in the export.
  3. Sign out, then sign up a fresh account with a new strong passphrase.
  4. From the new account, import your export file. You will be prompted for the old passphrase one last time to decrypt the file.
  5. Re-upload your videos into the matching entries.
  6. Once everything is verified in the new account, delete the old account from Settings → Account → Delete vault & account. You will have a 7-day cooling-off window before the data is permanently removed.

Export and import require a Personal plan or above.

Your vault is encrypted using AES-256-GCM with a key derived from your passphrase using PBKDF2 with 250,000 iterations and a unique random salt. Encryption and decryption happen entirely in your browser — your passphrase and vault contents never reach our servers.
No results found
View all help topics →
Still need help?
We respond within 48 hours for Personal and Family plans, same day for Firm.
0 / 500
🔒

Session locked

Your vault was locked after 15 minutes of inactivity.

Not your account? Sign out & clear session