CapitelistHelp Center

Security guide

Step-by-step guide

Held Away Assets

Use Held Away for private assets whose values may belong in net worth while access details must remain protected.

Held Away starts encrypted and excluded from normal totals.

Before you start

Use Held Away for private assets whose value may belong in your net worth while access details must stay protected. Held Away can include cold wallets, private metals, collectibles and physical cash. The core rule is simple: visible fields can describe value; sensitive recovery or location details belong only in protected storage.

You are in the correct portfolio.
You have created and safely stored the Recovery Key, or you are ready to do that first.
You know which private values should be visible in this session.
You know which details must stay protected: seed phrases, private keys, safe access, storage location or custody route.
You will hide Held Away again after review if you are done with private values.

Detailed steps

01

Read the protected Held Away banner

When Held Away is protected, private values are encrypted and excluded from totals, charts and analysis. This is intentional. Do not assume the portfolio is incomplete until you know whether Held Away should be included.

Held Away starts encrypted and excluded from normal totals.
02

Create the Recovery Key before protected records matter

If the Security prompt requires a Recovery Key, complete that setup before relying on Held Away. The Recovery Key protects private Held Away, Safebox and Legacy-sensitive data. Store it outside Capitelist before adding critical private records.

Create and store the Recovery Key before relying on protected private records.
03

Include Held Away only for the current review

Include Held Away when you need private values visible in the current browser session. Do this only in a private setting. If you are screen sharing, exporting or working on a shared device, keep Held Away hidden unless there is a deliberate reason.

Include Held Away only when you intentionally want private values visible in the current session.
04

Choose the protected asset type

Use Held Away options for cold wallet crypto, private metals, private collectibles or physical cash. Choose the type that matches the asset. Do not use normal visible assets when existence, location or recovery route should stay protected.

Use Held Away for protected cold wallets, private metals, collectibles and physical cash.
05

Save value fields without exposing secrets

For portfolio value, enter safe visible facts: asset name, value, currency, units or source note where appropriate. Never enter seed phrases, private keys, passwords, safe codes, exact hiding places or recovery instructions in ordinary visible fields.

After saving, verify value fields without exposing seed phrases or private keys.
06

Use Private Vault for recovery context

Open More details when you need to add protected recovery context. Private Vault should contain only the necessary custody route, document references and verification notes. Keep it specific enough to be useful, but do not expose it outside protected mode.

More details separates visible value from encrypted recovery context.
07

Hide Held Away when finished

After review, hide Held Away so private values leave the visible session. Recheck the banner before exports, screenshots, share links or screen sharing.

Hide Held Away again when you finish reviewing protected values.

Field guide

Include Held Away

Temporarily shows protected private values in the current session.

Use only when you intentionally need the private view.
Recovery Key

Offline key needed for protected data recovery.

Create and store it before relying on private records.
Visible value fields

Safe portfolio facts such as value, currency, units and source.

Do not add secrets or exact access routes here.
Private Vault

Protected place for sensitive custody or recovery context.

Use it instead of normal Notes for access-sensitive details.
Cold wallet crypto

Self-custodied crypto where access details must stay private.

Never store seed phrases or private keys in visible fields.
Private physical assets

Metals, collectibles or cash whose location or existence may be sensitive.

Keep exact storage and access instructions protected.
Hide Held Away

Returns private values to protected state.

Use it before sharing screens, exporting or leaving the device.

Decision rules

What it adds

  • Keeps your private wealth visible to you without exposing operational details by default.
  • Separates sensitive assets from normal exports and shared views.
  • Supports Legacy planning without putting secrets in regular notes.

What it does not do

  • Capitelist cannot recover encrypted private details without the correct recovery path.
  • Held Away values may be hidden from standard statements and exports.
  • Portfolio access does not imply access to Held Away secrets.

Common mistakes

What to check

  • Test your Recovery Key process before you need it.
  • Never store seed phrases, passwords or vault combinations in unprotected notes.
  • Document enough non-secret context for heirs to understand what exists.

Adding seed phrases, private keys or safe access details into ordinary notes.

Assuming portfolio collaborators can see Held Away because they can see the portfolio.

Including Held Away during a screen share without intending to expose private values.

Using visible Real Assets when a holding should be protected.

Forgetting to create and store the Recovery Key before adding critical private records.

Hiding all context so future recovery is impossible to understand.

Leaving Held Away included after the review is complete.

After you save

  • Check the Held Away row while private data is included.
  • Open More details and confirm visible value and protected context are separated.
  • Store recovery instructions only in protected areas.
  • Hide Held Away when finished.
  • Review Legacy Plan if trusted people may need to know that protected assets exist.
  • Exclude Held Away from share links or exports unless you intentionally need private disclosure.

Keep reading