Threat model

What Legatus does not protect against

Legatus protects a vault against server compromise, against any single nominee, and against release without evidence. It does not protect against a coerced passphrase, two colluding nominees, a forged death certificate that survives review, or the disappearance of Legatus itself. Those are the real limits.

Last reviewed 6 September 2026Legatus · Digital Legacy Vault

Coercion

Legatus cannot distinguish a passphrase entered willingly from one entered under duress. Any system where the owner can open the vault is a system where the owner can be compelled to open it. Encryption defends against people who do not have you; it does nothing against people who do.

There is no duress passphrase and no silent-alarm unlock. Adding one is not obviously an improvement: a decoy vault only helps if an attacker believes it is the real one, and a failed deception can make a bad situation considerably worse.

Two colluding nominees

The two-of-three threshold is the clearest structural weakness in Legatus. Two nominees who agree with each other can jointly confirm a transition that has not occurred. They would still need a death certificate that survives administrative review and would still face the 72-hour hold, but the first gate offers them no resistance.

The practical defence is choosing nominees who have no shared interest in your assets and, ideally, little contact with one another. Legatus cannot enforce that, and cannot detect it.

Administrative review is human, not authoritative

A death certificate uploaded to Legatus is reviewed by an administrator, not checked against a government registry. That review can be wrong in both directions: it can pass a convincing forgery, and it can delay a legitimate release over a document that is genuine but unfamiliar.

This is stated plainly because the alternative — implying a verification stronger than what actually happens — would be the more damaging error. It is one of three gates, and it should be weighed as a human review of a document rather than as proof.

A lost passphrase is final

If a Legatus vault owner forgets their master passphrase, the vault contents are permanently unrecoverable. Legatus cannot reset it, cannot recover it, and holds nothing that would help. This is the direct cost of the property that makes the system worth using, and it is not recoverable by support.

There are no backups

Legatus runs on Supabase’s Free plan, which does not include automated backups or point-in-time recovery. If the database were lost, corrupted, or the project were suspended, there is no restore path. Vault contents would be gone, and Legatus could not recover them for you.

This is the most consequential limitation on this page and it is a direct result of running a free service. It reinforces the recommendation below: a Legatus vault should never be the only copy of anything you cannot afford to lose.

Legatus itself is a dependency

If Legatus ceased to operate, vault contents stored on its servers would become unreachable. Legatus holds only ciphertext it cannot decrypt, so no third party could take over and open vaults on users’ behalf. A free service with no subscription revenue carries this risk more than a paid one does.

The honest recommendation: do not let a Legatus vault be the only copy of anything irreplaceable. It should be one component of an estate plan alongside a will and, for substantial assets, offline backups held somewhere you control.

What Legatus does not decide

Legatus determines who can open a vault. It does not determine who inherits its contents. Naming someone a nominee in Legatus is not a testamentary act, does not override a will, and does not displace legal heirs under Indian succession law.

QuestionDecided by
Who is entitled to the assets?Your will, or succession law where there is none
Who can technically open the vault?Legatus, via the nominees you designate
Who may exercise your data rights?Section 14 nomination under the DPDP Act, 2023

Where those answers point at different people, the legal ones govern the outcome. Why a nominee is not an heir covers this in detail.

What has not been independently audited

Legatus has not undergone a third-party cryptographic audit or penetration test. The algorithms it uses are standard and well-regarded — AES-256-GCM, PBKDF2, RSA-OAEP — but using sound primitives correctly is a separate claim from having had that use independently verified, and only the first can honestly be asserted here.

Readers comparing digital legacy services should ask every provider the same question, and should treat an unaudited implementation as unaudited regardless of which algorithms it names.