Skip to content

How to choose a dead man’s switch service: 9 questions to ask first

If you are going to hand a service your passwords, your documents and a letter to your family, you should make it earn that. This is the list of questions we would ask of any dead man’s switch, including ours. We have answered each one for My Signal Vault at the end of the section, so you can see where we stand rather than having to guess.

A note before the list: a service that answers every one of these with a confident, frictionless yes is not being straight with you. There are real trade-offs in this category and anyone who claims otherwise has either not thought about it or is hoping you have not.

1. What happens if the company goes under?

This is the first question and most sites bury it. A dead man’s switch is a promise about a date that may be twenty years away, made by a business that might not last five.

What to look for: a plain answer about what happens to your data if the service closes, and how much notice you would get. Be more suspicious of a confident guarantee than of an honest “we would give you notice and export your data”.

What to do regardless: do not let any single service be the only place your plan exists. Keep a paper copy of the critical recovery path somewhere safe. A switch should be the thing that delivers your plan reliably, not the only copy of it.

Us: we are a small operation and we will not pretend otherwise. Your files are downloadable at any time, your message is yours to copy, and we would rather you kept a paper backup of the essentials than relied on us alone.

2. Can staff read your files?

The honest answer for any service that can email an attachment to a recipient who has no account and no key is: something has to hold the key. True zero knowledge encryption and automatic email delivery to a layperson are mutually exclusive. You cannot have both.

What to look for: a service that explains exactly where encryption starts and stops. Vague phrases like “military grade” or “bank level” tell you nothing. Specifics tell you everything: which cipher, what is encrypted, where the keys live, and at what moment decryption happens.

The red flag: “zero knowledge” claimed alongside email delivery with attachments. Those two things cannot both be true.

Us: AES-256-GCM. Every file gets its own randomly generated key, and that key is itself encrypted before being stored. Files are encrypted block by block with a per-block authentication tag, and the full set of tags is fingerprinted so truncation is detected on read. Decryption happens on our server at the moment you download or a vault delivers — so this is not zero knowledge, and we will not describe it as if it were. What it defeats is every realistic attack on data at rest: a stolen bucket, a leaked backup, a misconfigured server. If you need more than that, encrypt the file yourself before uploading and give your recipient the passphrase another way. Our full position is in how your files are encrypted.

3. What does the recipient have to do?

Think about who is actually receiving this and in what state. It may be a seventy-year-old relative on the worst day of their life, using a phone they barely like.

What to look for: delivery that requires nothing of them. No account to create, no app to install, no password to enter, no link that expires in twenty-four hours while they are at a funeral.

The red flag: a download portal with a time limit. Every extra step is a place where this fails, and it fails at the exact moment there is nobody to ask for help.

Us: one email. Your message is the body, your files are attachments, and there is nothing to log in to. The limit is that email caps attachments at roughly 9MB in total, so a vault should carry documents and instructions rather than a media library. We explain how to work with that in attaching files to a vault.

4. How does it warn you before it fires?

The most common failure of a dead man’s switch is not that it fails to fire. It is that it fires when it should not have.

What to look for: multiple warnings before delivery, over more than one channel, and the ability to pause the whole thing before a trip.

The red flag: one reminder, by email only, shortly before delivery. Email gets filtered, mailboxes fill up, providers have outages.

Us: warnings at 75 and 90 percent of your interval, by email and by push notification if you have installed the app. Vaults can be paused indefinitely and armed again later. We still tell everyone to put a recurring reminder in their own calendar, because a safety net you control beats one you do not.

5. What intervals are available, and are they honest about the short ones?

What to look for: a decent range, and — more tellingly — guidance that steers you away from very short timers rather than selling them as a feature.

The red flag: a marketing page pushing hourly check ins. A one-hour timer on anything that matters is a promise you will break, and the people selling it hardest are rarely the ones who have thought about what happens when you do.

Us: one hour to thirty days, with presets, and any value in that range on the paid plans. Our own advice is in choosing an interval you will keep, and it amounts to: take the longest stretch you might realistically go offline, double it, and use that.

6. Is there an audit log you can actually read?

The genuine security risk to an account like this is not that somebody steals your message. It is that somebody quietly pauses your vault, so that it never sends, and nothing appears to be wrong.

What to look for: a complete record of every sign in, failed sign in, check in, change and delivery, with times and addresses, that you can filter and export.

Us: every action is logged with its time and the address it came from, filterable by category and event type, searchable, and exportable as CSV. Times are shown in the timezone on your profile rather than the device’s. See reading your audit log.

7. What is the sign in security like?

What to look for: two factor authentication with a standard authenticator app, backup codes issued when you enable it, a real lockout policy for repeated failed attempts, and the ability to sign out every device at once.

The red flag: no two factor authentication at all, or SMS as the only option.

Us: standard TOTP with any authenticator app, one-time backup codes issued at setup, and an escalating lockout — three failed attempts locks the address for 20 minutes, three more locks it for 24 hours. Sensitive endpoints are separately rate limited. Full detail in failed sign ins and lockouts.

8. What does it cost, and what happens if you stop paying?

What to look for: clear pricing, a free tier that is a real product rather than a trial, and a plain statement of what happens on downgrade.

The red flag: a service where lapsing means your data is deleted. Nobody should lose a letter to their family because a card expired.

Us: Free is 100MB and one armed vault, permanently, with no card. Paid plans add storage and more armed vaults. If a subscription lapses, nothing is deleted — but armed vaults over the new limit cannot stay armed, which is the consequence worth planning for. We set it out in what happens when your plan drops, and we would rather you read that before you need it. Any payment is refundable in full within 30 days.

9. Can you get your data out, and can you close the account properly?

What to look for: downloadable files, a readable copy of your message, and a real delete that actually removes things.

The red flag: no self-service deletion, or a “delete” that only hides the account.

Us: files download at any time. Deleting your account cancels any subscription first, then erases every vault, file, upload and audit record, and removes the account itself. One anonymous line stays in our security records noting that an erasure happened — no name, no address, a one-way hash as the reference — because that is the minimum a payment dispute needs. It is irreversible and we say so twice before you do it. See deleting your account.

The shortest version of this article

If you only ask three things, ask these:

  1. “What exactly can you decrypt, and when?” The answer tells you whether they understand their own product.
  2. “What does my recipient have to do?” The answer tells you whether they have thought about the moment it actually matters.
  3. “What happens if I miss a payment?” The answer tells you how they think about the people using it.

You can check our answers yourself. The help centre is written to be read before you sign up rather than after, the free plan needs no card, and if something in this article does not match what you find, we would genuinely like to hear about it — the contact form reaches a person.

Set up a vault of your own

The Free plan gives you one vault and 100MB of encrypted storage. No card, no expiry.

Create a free vault