Find accounts
What you’re seeing: Add, import, or review browser discoveries.
Why it matters: Start with the accounts you actually use—and the ones you forgot.

A client-encrypted vault, guided account discovery, deliberate autofill, a path toward passkeys, and recovery you prepare before you need it.
Controlled betaA guided path from forgotten accounts to stronger credentials and rehearsed recovery.

What you’re seeing: Add, import, or review browser discoveries.
Why it matters: Start with the accounts you actually use—and the ones you forgot.
What you’re seeing: Add, import, or review browser discoveries.
Why it matters: Start with the accounts you actually use—and the ones you forgot.

What you’re seeing: Create the client-encrypted vault and add unique credentials.
Why it matters: The vault solves the password problem, not merely documents it.

What you’re seeing: Approve a credential only for the exact matching HTTPS origin.
Why it matters: Nothing submits automatically and the extension does not store the password.

What you’re seeing: Open the provider’s real setup and confirm only after testing.
Why it matters: Trusted Entry guides the move without claiming to own the passkey.

What you’re seeing: Enroll a browser and rehearse an encrypted recovery kit.
Why it matters: Prepare for lockout before the emergency.

What you’re seeing: Request a prioritized plan from anonymous status labels and counts.
Why it matters: Get coaching without exposing vault contents.

Prepare a designated trusted contact or successor without turning Trusted Entry into a shared vault.
Real current or clearly labeled release-candidate states, using synthetic data.
Generate, save, reveal, copy, and remove credentials deliberately.
Discovery and the Fix queue keep the next step obvious.
Track provider-side passkey upgrades honestly.
Prepare and rehearse the paths that can unlock the vault.
Trusted Guide sees anonymous security labels and counts—not names, sites, usernames, secrets, notes, recovery material, ciphertext, or vault contents.
Choose the safest next few actions.
Plan for the unexpected: an optional designated trusted contact can support a future continuity path. Hosted delayed release is not yet a public operational guarantee.
Passwords and private notes exist as plaintext only in unlocked client memory. The master password is not sent to the API. Optional sync stores authenticated ciphertext that Trusted Entry cannot decrypt.
The service necessarily processes authentication, account metadata, device and operational state, continuity contact information, and limited audit data. Master-password recovery requires a device, tested recovery kit, or future operational continuity path prepared in advance.
Current behavior and boundaries.
Yes—when you choose to save or import them, Trusted Entry encrypts them in the client vault before storage or sync. The API cannot decrypt the vault.
No. Recovery requires a previously prepared trusted device, tested recovery kit, or future operational continuity release.
No. It opens the provider’s real setup page, tracks the migration, and asks you to confirm after the passkey works.
Anonymous security-status labels and counts, plus an optional screened question—not account identity, secrets, recovery material, or vault data.