Home › Blog › Secure Vault Guide
By DocFila Team · March 24, 2026 · 6 min read
Your phone holds more sensitive documents than you realize — tax returns, medical records, contracts, passport scans, financial statements, insurance policies, and legal agreements. If someone accesses your phone or your cloud storage is breached, all of those documents are exposed. An encrypted vault solves this by adding a dedicated layer of protection that goes far beyond your phone's lock screen.
A phone's lock screen protects the device itself, but it has significant gaps:
An encrypted vault stores each file as unreadable ciphertext. Even if someone copies the encrypted data, they cannot read it without your key.
DocFila's Secure Vault gives each file one of three protection levels. They are not the same, and it is worth knowing which one you picked:
Standard items sit behind the vault's PIN and biometric lock and are stored in DocFila's cloud storage on Google Cloud, which encrypts them at rest. DocFila does not encrypt a Standard item on your device first, so it is protected by the lock, your account and our storage rules — not by a key only you hold.
Encrypted items are sealed on your device with AES-256-GCM before they are uploaded. The key is either a random key kept in this device's secure storage (Keychain, Android Keystore or the platform equivalent) or one derived from a password you set, and DocFila's servers never receive it. The cloud copy is ciphertext. The flip side: an Encrypted item opens only on a device that holds its key, or where you type its password.
Offline-only items stay on this device and are never sent to DocFila's cloud. They are encrypted on the device only when zero-knowledge mode is on.
Turn it on and new vault files are encrypted on your device with a master key that is created there and never sent to DocFila. DocFila cannot decrypt those files. Zero-knowledge mode shows you a recovery phrase once; keep it somewhere safe, because DocFila cannot restore your files without the key.
A vault item's title, description, tags, size, type and date are stored as ordinary records so the vault can list and search them. Do not put the secret itself in a file's title.
Launch DocFila and tap "Secure Vault" on the home screen. If this is your first time, you will be prompted to set up authentication.
Choose a PIN you do not use anywhere else. It unlocks the vault on this device. If you add an Encrypted item with its own password, that password derives the item's key: if you forget it, no one — including DocFila — can recover that file.
Turn on Face ID or fingerprint unlock for quick daily access. Your PIN remains as a fallback for situations where biometrics are not available, such as when wearing gloves.
You can add files to the vault in several ways:
Choose Encrypted when you add a file if you want it encrypted on your device before it is stored. The original copy remains in its source location — delete it manually if you want only the vault version to exist.
Create folders for different categories: "Tax Documents," "Medical Records," "Contracts," "IDs & Passports," "Insurance." Add custom tags to files for cross-category searching. For example, tag a medical receipt with both "Medical" and "Tax Deductible."
Standard and Encrypted items are listed on every device where you sign in. A Standard item opens anywhere once the vault is unlocked. An Encrypted item opens only where its key is: on the device that created it, or anywhere you type its password. If you need a file on several devices, give it a password.
Any document you would not want a stranger to see belongs in an encrypted vault. Common categories include:
PIN and biometric lock, and on-device AES-256-GCM encryption for the files you choose.
App Store Google PlayKeep going with the document workflow that matches this page. Open the tool you need, then finish the file in DocFila.
Scan, sign, edit, translate, and store your documents in one app. Free to download, with optional paid features. No ads.
Or open the web app in any browser.