If you read nothing else, read this. It is the difference between a locked door and a lost life.
Nobody at BendFlex can open your vault, and — until a future update switches it on — neither can your recovery words. Right now your passphrase is the only way in. If you forget it, your data is gone permanently, and no amount of proving who you are, and no recovery card, changes that today. This is not a policy we could bend later either: we will never hold a key, a copy or a reset. We are only building a second door, not a back door.
This is what we are building toward. The only row below that works today is the first one, and even that one is "there is no way back" rather than a route in.
| If this happens | Today | The plan |
|---|---|---|
| You forgot your passphrase | No way back in | Your recovery card, or your guardians |
| The device is lost, stolen or dead | No way back in | Your backup file plus your recovery words, on a new device |
| You have died or cannot act | No way back in | Your guardians, together |
Nothing below this line in this section can be set up today — there is no guardian feature in the device yet, only the recovery card from Chapter 01. It is described here so you know the plan, and because choosing good guardians is worth thinking about before the day you need to.
A single card in a drawer is fragile. It gets lost in a house move, thrown out in a clean-up, or destroyed by the same fire as everything else. So the plan is for the device to split your recovery into three pieces given to three people, where any two together can open the vault and no single one can.
Each piece is real key material, not a receipt. Produce them offline, hand them over in person, and tell each guardian plainly: keep this like cash, never photograph it, never email it. Two pieces reaching the same email inbox undoes the whole arrangement. The options and their trade-offs are set out in Chapter 01.
There is no recovery drill on the device today. This is the plan, kept here so the design is written down.
Most people find out their backup never worked at the exact moment they needed it. So the plan is for the device to ask you, four times a year, to spend ten minutes proving it does.
There is no readiness screen on the device today. This mock-up shows the plan.
The idea is a home screen that keeps a running account of how recoverable you actually are.
It is meant to be slightly annoying. Everything on it is something that would matter enormously on one specific bad day.
The device slows down after a few wrong attempts: a few seconds, then longer, doubling each time up to a cap of one hour between tries. It is only a delay, and it exists to stop somebody standing at the device from guessing their way in.
The delay is not what makes a stolen device safe, and we would rather be straight about that. A thief does not stand there typing guesses. What protects you is that the storage itself is encrypted with a key the chip will not hand over, and that your passphrase is put through a deliberately slow calculation that makes bulk guessing expensive.
Which means your passphrase is doing real work. A long one you can remember is worth more than every other measure on this page.
There is no setting that wipes the vault after too many wrong tries. An elderly parent getting confused at the screen is far more likely than a burglar patiently guessing, and we will not build something that punishes the first to defend against the second. Wrong attempts make it wait. They never make it forget.
After twenty wrong attempts the device stops asking for the passphrase and tells you to use recovery instead — but today, with recovery-by-words not yet switched on, that message does not lead anywhere. It is a true statement about a door that is not open yet, so treat every attempt as one you cannot get back rather than something to retry twenty times to see what happens. Chapter 10 is honest about what that means.
BendFlex® Vault · Owner's Manual v2.1 · last updated 27 August 2026