A local-only encrypted vault for the files you'd rather not leave sitting in plaintext. No cloud, no account, no subscription.
Everything in the vault is encrypted under a single 256-bit Vault Master Key, generated once and never written to disk in the clear — it exists only in memory for the duration of an unlocked session. That key is unlocked two independent ways: a daily PIN, combined with a secret bound to this specific device, or a master password that stands alone as a recovery route. Either path produces the same key; neither one by itself is enough to reconstruct it.
Ten wrong PIN attempts in a row triggers a 24-hour lockout. Ten more triggers 72 hours. A third exhaustion doesn't lock the vault again — it destroys the keys. "Destroys" means deleting the handful of small key-material entries in secure storage, not overwriting the whole disk: without those few kilobytes, the ciphertext left behind is permanently unreadable, by anyone, including us. Authenticating with the master password clears an active lockout immediately, so a legitimate owner who triggers their own lockout isn't stuck waiting it out.
| Scenario | Outcome |
|---|---|
| Laptop is lost, stolen, or accessed by someone without your PIN or master password | Defended |
| Vault files copied to another machine or a USB drive | Defended |
| Repeated PIN guesses through the app's own unlock screen | Defended |
| Someone who already knows your PIN or master password | Not defended |
| Malware already running on your unlocked session | Not defended |
Full technical detail — Argon2id parameters, the physical-portability model, and the one known hardening gap we're tracking (a software-enforced lockout counter, not yet TPM-anchored) — is written up in the security architecture document.
A vault can be packaged into a single encrypted file — a random, meaningless name, sealed with a 6-digit PIN — and sent anywhere: email, cloud storage, a USB stick. Whatever carries it only ever sees ciphertext. Share the PIN a different way, over a call or a text, and it stays useless to anyone who only intercepted one of the two.
The person on the other end doesn't need to own Sovereign Vault. Sovereign Vault Opener is a free companion app: enter the PIN, choose a folder, done — no account, no purchase.
Download Sovereign Vault Opener — macOS, freeEffective date: 2026
Sovereign Vault collects no personal data, in any form, ever — this isn't a policy choice sitting on top of the app, it's a consequence of how it's built.
If this policy changes, the update will be posted at this same URL with a new effective date.
Most questions answer themselves:
Anything else — a bug, a crash, a question this page doesn't cover: mnemomemory@proton.me
Effective date: 2026
This is a license, not a sale. Aurora Apps grants you a personal, non-exclusive, non-transferable license to use Sovereign Vault on devices you own or control, subject to Apple's Licensed Application End User License Agreement and the terms below.
Questions about this agreement: mnemomemory@proton.me