Reference
Limits and roadmap
What GrailVault does not do today, its size limits, how it has been tested, and the ideas under consideration.
Security software should be honest about its limits. This page lists them.
#What it does not do today
| Missing | Notes |
|---|---|
| Native mobile apps and phone autofill | It works in the phone's browser and can unlock with the phone's lock. The extension runs in desktop browsers only. |
| Safari extension | Not available yet. |
| Sharing and teams | Every vault is private to one account. GrailVault is for individuals. |
| Offline mode | You need an internet connection to open the vault. |
| Autofill inside embedded frames | Some payment and single sign-on forms are not detected. |
| Filling items other than logins | API keys, SSH keys and the other developer types are stored but not filled into web pages. |
| Importing cards, bank details and identities | Only logins and notes are imported. |
| Email verification or password reset by email | Not included. Recovery uses the recovery key. |
| Email alerts for new sign-ins | The activity log shows them in the app; there are no emails. |
| Languages other than English | The interface is English only. |
#Security limits
- No independent audit. The design is documented so it can be reviewed, but no third party has audited it. We recommend an audit before relying on any password manager for something critical, including this one.
- A compromised service could serve altered code. This is a limit of every web-based vault. See How your data is protected.
- A compromised device is not protected against. Malware, a keylogger or a malicious browser extension can see what you type and see.
- Metadata is visible to the server: your email, the number, sizes and timestamps of your items, session details and your activity log.
- Older versions of an item are not detected. A server could return a previous copy.
- Clipboard clearing is best effort, and the extension popup cannot clear it at all.
- Sign-out does not erase a screen instantly. See Active sessions.
- Password strength is an estimate. The security check is strict about common patterns but cannot know everything.
#Size limits
| Limit | Value |
|---|---|
| Items per account | 20,000 |
| Size of one item | about 256 KB |
| Rows in one import file | 20,000 (file size up to 10 MB) |
| Signed-in devices per account | 20 (the oldest are signed out first) |
| Device unlock entries per account | 10 |
| Two-factor backup codes | 8 at a time |
| Items in one encrypted backup file you restore | 5,000 |
| Encrypted backup file size | 50 MB |
| Website sign-in length | 12 hours (no idle timer) |
| Extension sign-in length | 7 days (and until the browser closes) |
| Recent activity kept | the newest 500 events from the last 180 days |
#How it has been tested
Automated tests cover the server, the encryption, the importers and the extension's matching rules. Browser tests drive the real app and the real extension through the main flows: sign-up, sign-in, import and export, fill, save, update, lock, sign-out, the free trial and read-only mode, and the security check including the live breach lookup. The server's tests also run on PostgreSQL.
Not tested, or tested only partly:
- Browsers: the automated browser tests run in Microsoft Edge. Other current browsers should work, but they are not tested. The Firefox extension build has not been run.
- Device unlock was verified with Windows Hello. Support on phones, Macs and iPhones depends on the device and browser and has not been verified on real devices.
- Online payment follows the payment service's documented interface and is tested with simulated payment events, not yet with a live account.
- The container setup for running the service has not been run.
#Ideas under consideration
These are ideas, not promises or dates:
- A mobile app with autofill.
- A Safari extension.
- Alerts for sign-ins from new devices.
- Detecting rolled-back data.
Missing something important? Contact us using the details on our website.