Private photos, documents and notes

A passcode you can afford to give away.

Vessum keeps your photographs, documents and notes behind more than one passcode. Each one opens a different space. Hand over the passcode you are willing to lose, and whoever types it finds a real, working, ordinary app. Nothing on the phone can show them there is anything else.

No account · no server · nothing ever leaves the phone
21:17
Vessum
Enter your passcode
Everyday

Two of those open something. One does not. Nothing on the screen tells you which is which, or how many more there are.

How it works

One app. As many spaces as you need. No way to count them.

The idea is old and well understood. What matters is that it is built properly, because a decoy that can be spotted is worse than no decoy at all.

1

Fill the space you keep

Photographs, documents and notes go into your own space, encrypted with a key that exists only while you are typing your passcode. This is the passcode you never hand over.

2

Build one to hand over

Create a second passcode with a space of its own, and put real, ordinary things in it. Old receipts, holiday photographs, an insurance document. A space that opens onto nothing tells whoever opened it to keep asking.

3

Give up the one you chose

Under pressure, you give the passcode you prepared. It opens a complete, working app with its own settings and its own contents. There is nothing on the phone that says anything else is there.

The slot test

Find the vaults.

This is not an illustration. Your browser is about to run the same cryptography the app runs, on this page, right now. Some of the slots below hold a real encrypted space. The rest are random noise. Pick the ones you think hold something.

Preparing twenty-four slots.

AES-256-GCM · PBKDF2 150,000

Scaled down so it fits on a screen: each slot here is 256 bytes, where the app uses 256 KB, and there are twenty-four of them exactly as there are in the app. Everything else is the real thing. The key comes from PBKDF2-HMAC-SHA256 at 150,000 iterations over a per-slot salt, the payload is padded to a constant size and sealed with AES-256-GCM, and the empty slots are filled straight from your operating system’s random number generator. Nothing is sent anywhere. View the source of this page if you would like to check that.

Nesting

Every space can hide another, and none of them looks up.

This is the part that other vault apps get wrong. If the decoy is missing a feature the real one has, then anybody who has seen the app before can spot it in a second, and the person who handed over that passcode is worse off than if they had never had the app at all.

Personal
Your space. Settings can create more.
Everyday
Opened by the passcode you gave away. Identical settings. Can create more of its own.
Work
And so on, as deep as you want to go.

Every level is the same app. Same settings screen, same sections in the same order, same wording, same ability to create and remove spaces of its own, same error messages. There is not a single branch in the app that depends on which space is open.

A space lists what it created, never what created it. There is nothing written down that points upwards, so there is nothing to display and nothing to recover. You can walk down the tree. You cannot walk up it.

So there is no top. Somebody who opens a space has no way to tell whether they are at the first one you made or three levels beneath it. Not by looking, not by counting, and not by reading the disk.

The difference

Most apps with a “decoy password” are showing you a different screen.

The feature has existed for a decade. What usually sits behind it is an interface that checks which of two stored passcodes you typed, which is a very different thing from what is described here.

 
The usual decoy
Vessum
Where the passcodes live
Stored on the device and compared, so recovering the database recovers both.
Nowhere. Nothing to recover. A passcode is only ever typed.
Does a second space leave a trace
Usually yes, as a flag or an extra row that says plainly that one exists.
No. Every slot is the same size and full from the first launch.
Can the decoy be spotted
Often, because it is missing features the real one has.
No. Every space is the same app, all the way down.
Where your content goes
Frequently the vendor’s cloud, under the vendor’s key.
Your phone. There is no network code in the app at all.
What deleting really does
Removes the file, which flash storage does not honestly overwrite.
Discards the key. The bytes stay as noise and can never be read again.
What you get

An ordinary document app, built carefully.

Nothing about Vessum announces itself. No padlock on the icon, no warnings, no red screens. It looks like somewhere you keep paperwork, because that is the most useful thing it can look like.

Photographs, documents and notesImport from your library or from Files, write notes in the app, and export anything back out when you need it.
Up to twenty-four spacesArrange them side by side or nested inside one another, in whatever shape fits the situation you are preparing for.
AES-256-GCM, per itemEvery file gets its own key. Those keys exist in exactly one place, inside the encrypted manifest of the space that owns it.
Closes the moment you leaveSwitching apps closes the open space, and the app switcher preview is covered before iOS takes its snapshot.
Out of every backupThe store is excluded from iCloud and from computer backups, so it cannot be lifted off a machine that backed your phone up.
Decoy files by defaultThe app writes random files of realistic sizes at setup, so the number of files and the space they take say nothing about what is really there.
Being straight with you

What Vessum cannot do.

If you are relying on something like this, you are owed the limits in plain words rather than a marketing claim. Here they are.

It cannot hide your other apps

No iOS app can show or hide your banking app, your photo library or your messages. It cannot register a second device passcode or replace the Home Screen. Those are system powers with no way for an app to request them, and anything on the App Store claiming otherwise either is not doing it or needs a jailbreak. What Vessum protects is what you move into Vessum.

It is not a defence against a laboratory

Vessum is built for somebody holding your phone and demanding a passcode. It is not built against a full forensic extraction of the device by people with the right equipment and unlimited time. If that is the situation you are preparing for, the honest advice is to not carry the data at all.

Its own presence is not a secret

Anyone who looks at the phone can see that Vessum is installed and that it holds encrypted data. That part cannot be hidden and we will not pretend it can. What stays hidden is how many spaces exist and what is inside them.

A forgotten passcode is gone

There is no reset, no recovery code and no support address that can be leaned on, because your passcode is not stored anywhere, not even on your phone. If you lose it, the space it opened is unreadable forever. The app asks you to confirm you have understood that before it creates anything.

Privacy

There is nothing for us to hand over.

Vessum has no account system, no server and no analytics. It makes no outbound network connection, because it contains no code that could. We could not identify a single user of this app if we were asked to, and we would have nothing to give if we were compelled to. That is not a policy we are promising to keep. It is a consequence of how the app is built.

Read the privacy policy

Decide in advance which passcode you are willing to lose.

Pay once. No subscription, no in-app purchases, no ads, and nothing collected.

Requires iPhone or iPad with iOS 17 or later.