CapitelistHelp Center

Security guide

Coming soon

Recovery Key and Private Unlock

Recovery Key and private unlock protect Held Away, Safebox and Legacy-sensitive data.

Current Capitelist screen for Recovery Key and Private Unlock.

Before you start

Decide what should be visible in normal workspace views and what must stay protected. Sensitive access details belong in encrypted/private areas, not ordinary notes or shared exports.

You know whether private data is currently hidden or included.
Sensitive details are ready to be stored only in protected fields.
You know who should and should not see this information.

Detailed steps

01

Open Settings > Keys or the private unlock prompt

Start from the screen named in the step and confirm the portfolio in the top bar before you change anything. If the wrong portfolio is selected, switch portfolios first.

02

Create and store the Recovery Key using the instructions shown in the app

Use this step to turn loose information into a clear portfolio record. If you are missing an input, note the gap instead of guessing.

03

Use passkeys or approved unlock methods on trusted devices

Use the option named in the step only when it matches your source. If the source is weaker than the label suggests, record the uncertainty instead of making the value look more precise.

04

Lock private mode when you are done reviewing sensitive data

Use this step to turn loose information into a clear portfolio record. If you are missing an input, note the gap instead of guessing.

Field guide

Visibility

Who can see the record in normal use.

Keep private operational details out of standard fields.
Recovery context

How the information can be understood later.

Document non-secret context clearly.
Protected notes

Sensitive details encrypted behind private controls.

Never store raw secrets in regular notes.
Release level

What a trusted person may receive.

Match the role and relationship deliberately.

Decision rules

What it adds

  • Protects sensitive records from routine workspace exposure.
  • Creates a defined recovery route for heirs or trusted contacts.
  • Keeps private data encrypted beyond normal app access.

What it does not do

  • Capitelist cannot read encrypted secrets without your unlock material.
  • Lost recovery material can make protected data unrecoverable.
  • Unlocking private mode is a local session state, not a permission grant to everyone.

Common mistakes

What to check

  • Do not store the Recovery Key inside the same vault it unlocks.
  • Review who can access the device used for passkeys.
  • Lock private mode before screen sharing or exporting.

Entering a clean-looking value without recording where it came from.

Ignoring currency, ownership percentage or valuation date because the total appears reasonable.

Using ordinary notes for private access information.

Assuming Recovery Key and Private Unlock produces advice, verification or execution beyond the workflow described here.

After you save

  • Return to Net Worth and confirm totals changed as expected.
  • Open Capital Review to see whether the record created, resolved or changed any review item.
  • Check whether the record should affect Forecast, Investment Plan, exports or share links.
  • Revisit this security guide when source evidence changes.

Keep reading