CapitelistHelp Center

Security guide

Step-by-step guide

Create and Store the Recovery Key

Create your Recovery Key and store it outside Capitelist so protected Held Away, Safebox and Legacy data remain recoverable.

Start in Settings > Keys when you want to check whether private recovery is already configured.

Before you start

Create the Recovery Key only when you are ready to store it outside Capitelist. The 16 words unlock protected private data such as Held Away details, Safebox notes and Legacy-sensitive instructions. Capitelist cannot show the words again after setup, so this step matters before you add critical private records.

You are in a private place and nobody else can see your screen.
You have an offline or separate trusted storage location ready.
You understand that the 16 words must stay in the same order.
You will not save the words inside the same Capitelist account or Safebox area they unlock.
You know who, if anyone, should be able to access the key in an emergency.
You can pause if you are screen sharing, recording or using an untrusted device.

Detailed steps

01

Open Settings > Keys and check current status

Go to Settings and open Keys. If the Recovery Key says Not created yet, protected data cannot be recovered through this account until you complete setup. If it already says Created, do not create another key; check the checksum and trusted-device section instead.

Start in Settings > Keys when you want to check whether private recovery is already configured.
02

Start from the Security prompt when protected data is blocked

You may also see the Security prompt when you try to include Held Away or open another protected area. Use Create Recovery Key from that prompt when you need private data to become recoverable. Cancel if you are not ready to store the words properly.

Protected data stays blocked until you create the Recovery Key or unlock with an approved method.
03

Read what one Recovery Key unlocks

Before generating the words, read the list of protected areas. The same key can unlock Held Away locations, Legacy instructions, final messages, Safebox notes, sensitive documents and future encrypted recovery data. Continue only if you are comfortable with that scope.

Read the warning before generating words because the key protects Held Away, Safebox and Legacy-sensitive data.
04

Generate the key and copy the 16 words offline

When the words appear, copy them exactly as shown and keep them in order. Do not translate, pluralize, reorder or clean them up. Use a physical copy, a secure offline vault or another storage method that remains available if this device or account is unavailable.

The generated words are shown once in the product. They are hidden in this help screenshot on purpose.
05

Confirm the 16 words before saving

Type the words into the confirmation box in the same order. Save only when the app confirms all 16 words match. If the match fails, stop and compare the copy before saving. A wrong copy can make protected data impossible to recover later.

Confirmation proves the copied words match before you save. The help screenshot hides the key.
06

Save the key and keep the checksum with your copy

After saving, Capitelist shows created status and a checksum instead of showing the words again. Write the checksum next to your offline copy so you can later confirm you are looking at the right Recovery Key without exposing the full words.

After saving, Capitelist shows created status and checksum, not the 16 words again.
07

Return to Settings > Keys after setup

Open Settings > Keys again and confirm the Recovery Key says Created. Review the checksum, creation date and Trusted devices section. Trusted devices or passkeys are useful for daily unlocks, but they do not replace the offline Recovery Key.

Use Settings > Keys later to check created status, checksum and trusted-device state.
08

Unlock protected data only when you need it

Use the Security unlock prompt when you need Held Away, Safebox or Legacy-sensitive data visible in the current session. If you create a passkey, use it only on a trusted device. Hide or lock private data again before screen sharing, exporting or leaving the device unattended.

Use the unlock prompt only when you need protected data visible in the current session.

Field guide

Recovery Key

The 16-word offline fallback for protected private data.

Keep the words exact, ordered and outside Capitelist.
Checksum

A short identifier that helps confirm you have the right key without exposing the full words.

Store it with the written copy and compare it in Settings > Keys.
Confirm Recovery Key

The verification box that proves your copy matches before saving.

Do not save until the app confirms all 16 words match.
Printable sheet / text file

Export options offered during setup so you can store the key outside the browser.

Use the option that fits your storage policy and protect the exported file immediately.
Trusted devices

Devices or passkeys that can unlock protected data after Recovery Key setup.

Remove devices that are lost, sold, shared or no longer trusted.
Security unlock

The modal that makes protected data visible in the current session.

Unlock only when you need the data and hide it again afterward.

Decision rules

What it adds

  • Provides the controlled recovery path for encrypted private data.
  • Reduces the risk that trusted people know records exist but cannot access the instructions.
  • Keeps Capitelist from needing to hold readable private secrets.

What it does not do

  • Capitelist cannot regenerate a lost Recovery Key for encrypted content.
  • A screenshot of the key stored in the same compromised account is not safe storage.
  • Support should never ask you to reveal the full Recovery Key.

Common mistakes

What to check

  • Store the key offline or in a separate trusted vault.
  • Never give the full key to a person who should not access private records.
  • Update the recovery plan when trusted people or storage locations change.
  • Do not put the key inside Safebox if Safebox depends on that key.

Taking an ordinary screenshot of the 16 words and leaving it in Photos, Downloads or a shared folder.

Sending the Recovery Key through email, chat, support tickets or an advisor message.

Saving the key inside Safebox or another protected area that depends on the same key.

Changing the words, translating them, adding punctuation that changes meaning or reordering them.

Treating a passkey as a replacement for the offline Recovery Key.

Creating the key while screen sharing or while another person can view your screen.

Assuming Capitelist support can recover the words later.

After you save

  • Check Settings > Keys and confirm the Recovery Key status is Created.
  • Store the checksum with the offline copy so you can identify the key later.
  • Decide whether to create a passkey on this device for daily unlocks.
  • Test the Security unlock once before adding important Held Away, Safebox or Legacy-sensitive records.
  • Hide protected data when you finish reviewing it.
  • Update your personal recovery instructions when storage location or trusted people change.

Keep reading