Reference

Limits and roadmap

What GrailVault does not do today, its size limits, how it has been tested, and the ideas under consideration.

Security software should be honest about its limits. This page lists them.

#What it does not do today

Missing Notes
Native mobile apps and phone autofill It works in the phone's browser and can unlock with the phone's lock. The extension runs in desktop browsers only.
Safari extension Not available yet.
Sharing and teams Every vault is private to one account. GrailVault is for individuals.
Offline mode You need an internet connection to open the vault.
Autofill inside embedded frames Some payment and single sign-on forms are not detected.
Filling items other than logins API keys, SSH keys and the other developer types are stored but not filled into web pages.
Importing cards, bank details and identities Only logins and notes are imported.
Email verification or password reset by email Not included. Recovery uses the recovery key.
Email alerts for new sign-ins The activity log shows them in the app; there are no emails.
Languages other than English The interface is English only.

#Security limits

  • No independent audit. The design is documented so it can be reviewed, but no third party has audited it. We recommend an audit before relying on any password manager for something critical, including this one.
  • A compromised service could serve altered code. This is a limit of every web-based vault. See How your data is protected.
  • A compromised device is not protected against. Malware, a keylogger or a malicious browser extension can see what you type and see.
  • Metadata is visible to the server: your email, the number, sizes and timestamps of your items, session details and your activity log.
  • Older versions of an item are not detected. A server could return a previous copy.
  • Clipboard clearing is best effort, and the extension popup cannot clear it at all.
  • Sign-out does not erase a screen instantly. See Active sessions.
  • Password strength is an estimate. The security check is strict about common patterns but cannot know everything.

#Size limits

Limit Value
Items per account 20,000
Size of one item about 256 KB
Rows in one import file 20,000 (file size up to 10 MB)
Signed-in devices per account 20 (the oldest are signed out first)
Device unlock entries per account 10
Two-factor backup codes 8 at a time
Items in one encrypted backup file you restore 5,000
Encrypted backup file size 50 MB
Website sign-in length 12 hours (no idle timer)
Extension sign-in length 7 days (and until the browser closes)
Recent activity kept the newest 500 events from the last 180 days

#How it has been tested

Automated tests cover the server, the encryption, the importers and the extension's matching rules. Browser tests drive the real app and the real extension through the main flows: sign-up, sign-in, import and export, fill, save, update, lock, sign-out, the free trial and read-only mode, and the security check including the live breach lookup. The server's tests also run on PostgreSQL.

Not tested, or tested only partly:

  • Browsers: the automated browser tests run in Microsoft Edge. Other current browsers should work, but they are not tested. The Firefox extension build has not been run.
  • Device unlock was verified with Windows Hello. Support on phones, Macs and iPhones depends on the device and browser and has not been verified on real devices.
  • Online payment follows the payment service's documented interface and is tested with simulated payment events, not yet with a live account.
  • The container setup for running the service has not been run.

#Ideas under consideration

These are ideas, not promises or dates:

  • A mobile app with autofill.
  • A Safari extension.
  • Alerts for sign-ins from new devices.
  • Detecting rolled-back data.

Missing something important? Contact us using the details on our website.