Vault and encryption
How your encrypted vault is protected by default, and how to lock it with your account password or a master passphrase.
One encrypted vault#
Hosts, passwords, key passphrases, imported keys, snippets and settings live in a single vault file sealed with AES-256-GCM. Nothing readable is written next to it, not even host names. Saves are atomic, so a crash while saving cannot cost you your host list.
How the vault is opened#
Settings → Security shows how your vault is protected:
| Mode | Behaviour |
|---|---|
| Automatic (default) | The key sits in a key file beside the vault. Ravelon opens without asking. |
| Account password (opt-in) | The key is derived from your Ravelon account password with Argon2id. Nothing usable is left on disk. |
| Master passphrase (opt-in, no account needed) | The same, with a passphrase chosen only for this vault. |
Turn on the lock#
Under Settings → Security → Lock, switch on Require the account password at launch. You need to be signed in to your Ravelon account first. Ravelon cannot reset this password: without it, or a copy remembered on this device, the vault cannot be opened. You can let one device remember it so that it still opens without asking there.
On a device that never signs in, choose Protect the vault with a separate passphrase instead. The passphrase needs at least 8 characters.
Lock and auto-lock#
With a lock turned on, lock the vault with Lock vault in the menu behind your avatar, or with ⌘⇧L on macOS or Ctrl+Shift+L on Windows and Linux. Lock automatically locks the vault after 5 minutes to 4 hours without input in Ravelon, and when the computer wakes after a longer sleep. Locking closes every SSH session with its tunnels and file transfers, and every remote desktop.
If the vault cannot be opened#
Ravelon then shows a recovery screen with real actions: try again, reveal the folder, or start over. Starting over archives the unreadable file next to the new one. Nothing is deleted.
Last updated 30 September 2026