Getting started

Setting up your encryption passphrase

How docEvault's end-to-end encryption works, how to choose a passphrase, and why nobody can recover it for you if it's lost.

docEvault uses end-to-end encryption for documents in your vault. Your organization generates its own encryption keypair in the browser, and the private key is protected by a passphrase only your organization knows. docEvault's servers store documents encrypted and cannot read their contents.

Setting it up

On first login you'll be prompted to set up encryption with the Encryption Setup flow. Choose a strong passphrase — this passphrase wraps your organization's private key.

docEvault cannot recover this passphrase for you. There is no backend override and no support ticket that can reset it. Store it in a password manager before you need it.

Choosing a passphrase

  • Use a password manager to generate and store it. This is the single most important thing you can do here.
  • Make it long. A passphrase of several random words beats a short complicated string.
  • Don't reuse your login password. They protect different things, and resetting one does nothing to the other.

How your team gets access

Any team member you invite later needs this same passphrase, or needs to be granted access by an existing member from their own session. Plan for this before you invite people — if the only person who knows the passphrase is unavailable, new team members can't unlock existing documents.

For that reason, more than one person at your organization should be able to unlock the vault. A passphrase known to exactly one individual is an outage waiting to happen.

If it's lost

Losing the passphrase means losing access to encrypted documents. If another team member still has access they can grant it to you from their session. If nobody does, previously encrypted documents are not recoverable — see Forgot your encryption passphrase.

This is a deliberate design choice rather than a limitation. A vault your provider can unlock on request is a vault your provider can be compelled to unlock.

Didn't find what you needed? Email support@docevault.com with your organization name and, if it's about a specific request or contact, which one.

Last updated 2026-08-25