What updates will look like, what already exists to make them safe, and how to check what you are running today.
You cannot install an update on the device today — there is no Update button and no way to send it a file yet. What exists already is the part underneath: a way to check, cryptographically, that an update file genuinely came from BendFlex and was not tampered with in transit. Installing what passes that check is still being built.
| Part | What it is | How often |
|---|---|---|
| Firmware | The software that runs everything | A few times a year, once updates can be installed |
| Assistant | The plain-language search — off by default and not part of what ships today; see Chapter 03 | Not yet available |
Updates are planned to be free for the life of the device. There is no subscription and nothing expires.
None of these three routes exist on the device yet. This is the plan, so you know what to expect once it lands.
An update file carries a signature from us over its contents, and the device verifies it before treating the file as trustworthy at all — a file that is not genuinely ours, or that was altered after we signed it, fails that check. This part is built and tested today. What is not built yet is installing: writing a verified update into flash at all. There is no dual-slot switch-back today, and we are not promising the shape that will take — the safe-rollback platform code we build on marks a new update as good the moment it boots, before anything has proven it actually works, which is the opposite of automatic protection until that is deliberately changed. Until installing exists at all, none of this is something your device does.
This part is real today, and it is the answer to "what version am I on" for a call to support. With the device plugged in or on its own Wi-Fi (Chapter 02), open a browser to http://vault.local/api/version — or the numeric address shown on the device screen with /api/version after it. You do not need to unlock the vault first.
It is one dense line, not meant to be read like a sentence — it exists so you can copy the whole thing into an email or a support form and have us read exactly what your unit is running, without asking you to unlock anything or type your passphrase over the phone. ai=none means no assistant model is installed, which is the normal state today (see Chapter 03). fw= is the firmware version; the rest identify the exact recovery wordlist, key-derivation settings and hardware revision your unit is running, which matters more than it sounds — two units with different values there cannot open each other's vaults even with the right passphrase.
The plan is a QR code, readable without unlocking, that opens a manual matched to your unit directly — built from just hw and fw above, never the rest of this line and never your serial. Not built yet, on the device or the website: see Chapter 11.
The plan is that the device will not start software we have not signed, closing off someone replacing your firmware with something that quietly copies your vault. That enforcement is not switched on yet. It also means, once it is, you will not be able to install your own software on hardware you paid for. We would rather say that plainly here than have you discover it later.
The plain-language search is not shipped, not installed, and off by default — there is nothing to label beta because there is nothing running. When it does arrive, it is built so it can never see a password, a document, or any other secret, and it will never invent a password — when unsure it will say so. We will update this chapter with a real status once there is one.
BendFlex® Vault · Owner's Manual v2.1 · last updated 27 August 2026