It is the question every owner asks about five minutes after signing up, and then never asks again: what if my password manager gets hacked?

It is a fair question, and the honest answer is not “it will not happen”. Password managers are among the most attractive targets on the internet, precisely because of what they hold. The useful question is narrower and much more uncomfortable.

If they are breached tomorrow, what does the attacker actually walk away with, and what does that cost you?

Know what an attacker actually takes

In a classic password manager, the answer is one object: your vault.

It is encrypted, and the provider cannot read it. But it is complete, and once it is copied it is on their hardware and their timetable. No rate limits, no lockouts, no alerts on failed attempts. It becomes an offline attack against one master password, running for as long as they care to run it.

That is the part most people miss. The strength of the encryption stops mattering the moment the whole ciphertext leaves the building. From then on, everything depends on how good one person’s password was, and on how old the vault’s key derivation settings are.

One object, one secret, one chance. That is the shape of the risk.

Skip the panic rotation of everything you own

The second cost arrives before you know anything for certain.

You cannot tell what was in the vault at the moment of the breach, so the safe assumption is all of it. Weeks go into rotating every credential in the company, badly, while people wait to work. Half of it was never at risk, and you will never learn which half.

Meanwhile the accounts that matter most are the ones that are hardest to rotate: the bank, the domain registrar, the cloud root account, the payroll portal. Those are the ones you postpone, and postponing is exactly what an attacker is counting on.

Find out from a record, not from a press release

The third cost is time, and it is the one that stings.

Reading leaves no trace. A copied vault does not raise an alarm, and neither does a credential quietly used once. Most companies learn about it from the provider’s blog post, months later, worded carefully.

An audit trail changes what you know and when. In Inheriti® Business every access request, every approval and every reveal is written down as it happens, with the person, the role, the time and the plan. If something is opened that should not have been, that is a line in a record on the day it happens, not a reconstruction a quarter later.

Comparison: a breached password manager gives up one encrypted vault behind one master password, while Inheriti splits a secret into shares across multiple storage layers
A breached vault leaves in one piece. Shares spread across multiple layers give up nothing on their own.

A secret that is not stored whole cannot be stolen whole

Now the architectural part, because this is where the answer stops being about behaviour.

Inheriti® Business does not keep a vault. A data asset is encrypted in your browser, and the result is split with Shamir’s Secret Sharing into data shares, key shares and a custodian share pair. Each share is separately encrypted with a per plan key, which is itself wrapped with the organisation key and sealed with a key pair that never leaves the Inheriti® HSM.

Those pieces then live in different places: the Inheriti® Vault, the organisation’s own smart contract on InheritiChain, and a separate custodian depot. No single location holds enough to reconstruct anything.

So the question changes shape. Breaching one storage layer does not produce an encrypted copy of your secrets, waiting to be cracked. It produces pieces that are useless on their own, and an attacker who now needs to breach several unrelated systems at once, and still lacks the keys.

The provider must not be able to open it either

There is a version of this question people are too polite to ask out loud: what if the problem is you? A rogue employee, a court order, a compromised administrator.

The answer has to be structural, because a promise is not a control.

The organisation key is derived in your browser from a PIN the owner memorises, using Argon2id with a random salt. Only the salt and a verificator are stored, and the verificator lets the system check the PIN without reversing it. The PIN and the organisation key never reach our servers. We cannot open what we do not have.

A reveal needs several things at the same moment: an authorised member of the right team, the organisation key released from their own device, the distributed shares, the plan key unsealed by the HSM, and the approvals the plan requires. There is no path through that from a single stolen database, and no path through it from our side either.

What Inheriti® does about it, and why you need it

A breach at a password manager is a bad day for them and a bad quarter for you, because the design concentrates everything you own into a single object protected by a single secret. Nothing about your own habits changes that shape.

Inheriti® Business is built so that a breach anywhere gives up as little as possible:

  • There is no complete copy to steal. Encryption happens on your device, and the result is split into shares distributed across multiple storage layers.
  • There is no single secret to crack. No one key opens a plan, and the organisation key never leaves your side of the connection.
  • We are not a shortcut. Non-custodial by design: the provider cannot decrypt your data, so compromising us does not compromise you.
  • You are not guessing afterwards. The audit trail tells you what was actually requested, approved and revealed, so you rotate a short list instead of everything.
  • Your rules still apply under pressure. Team scoping, moderator approvals and authentication are enforced on every reveal, including through the Dead Man Switch, which is an extra gate and never a bypass.

That is why this is not simply a better vault. It is the removal of the thing that makes vault breaches so expensive: the single complete object, behind the single memorised secret.

Where to start this week

Ask what would leave the building if your current provider were breached tonight. If the answer is “everything, in one file”, that is the finding.

Pick the credentials you would not be able to rotate quickly. Banking, registrar, cloud root, payroll. Those are the ones that deserve to be split rather than stored.

Move those into a plan in Inheriti® Business, scoped to the team that needs them, with the approvals that reflect how you work. Then delete the copies that are still lying around, because the move is only finished when they are gone.

See how Inheriti® Business works.