Verified answer

What is the real key to a digital vault, and how should it be stored?

A metal key opens a physical safe. Vault's 12-word phrase restores decryption ability. The daily password and Face ID control access on the current device, the Apple Account controls access to CloudKit records, and the phrase retains final disaster-recovery authority. They are not the same key.

Author: 曜郡 刘App Store version: 1.0Verified: 2026-09-14
What the evidence says

The answer, step by step

  1. 01
    The 12 words are the recovery key

    Words, order, and spelling determine the device-derived decryption key. The phrase is not written to CloudKit.

  2. 02
    The password is the daily lock

    The daily password protects current-device access. If forgotten, the complete phrase and available ciphertext provide the recovery path.

  3. 03
    Face ID is local authorization

    Face ID is tied to current biometric enrollment. It is convenient local access, not a cross-device recovery credential.

  4. 04
    The Apple Account is the cloud address

    It controls who can retrieve CloudKit records, but signing in alone should not reveal plaintext.

  5. 05
    Separate key from safe

    Write the phrase on durable offline media in a physical safe or controlled location. Do not screenshot, photograph, email, or store it inside Vault.

VERIFICATION METHOD

How to check this claim

Run a non-sensitive recovery drill: enter the complete phrase and confirm GCM authentication succeeds, then change one word and confirm recovery fails clearly.

See the full verification protocol →
Limits

What this answer does not claim

Anyone who obtains both the complete phrase and matching ciphertext may have the conditions to decrypt it. Physical backups also face loss, fire, water, and observation risks.
FAQ

Direct answers

How is the password different from the phrase?

The password protects daily access; the phrase provides final recovery. Remembering the password does not replace keeping the phrase offline.

Can Face ID recover a new iPhone?

No. Face ID is local-device authorization, not a cross-device recovery key.

Can I keep the phrase in iCloud Notes?

It is not recommended. That places ciphertext and its final key in a similar online risk domain and weakens separated custody.

Primary sources

References used

Continue