Local-first: who
backs up your vault?
Keeping passwords on your device reduces exposure. But with no server remembering everything for you, backing up becomes your job.
A local-first password manager stores your data on your device rather than on a third party's account. Upside: fewer exposure points. Trade-off: if the device is lost, stolen, or fails, there is not necessarily a copy somewhere you could "just" recover.
This article is not about one brand: it lays out the habits that keep a disk failure from becoming the loss of all your access.
01 / THE TRADE-OFFLocal-first: less exposure, more responsibility
When your data lives only on your device, it does not depend on the availability or security of a third-party service. That is a real gain. But the flip side is symmetric: nobody else holds a copy for you.
Three real situations are enough to make the point: the laptop stolen on a train, the disk that fails without warning, the system reinstall that wipes everything. In all three, the question is not "did it happen to someone else?" but "do I have a copy that works?"
LOCAL VAULT · YOUR DEVICE
02 / THE 3-2-1 RULEA principle as old as backups, still valid
In its Data Backup Options guide, CISA recommends the "3-2-1" rule: three copies of your data, on two different media types, with one copy kept off-site.
For a password vault, that could be: the vault on your computer, a copy on an external drive, an encrypted copy elsewhere (another place, another medium). What matters is that a single incident cannot destroy every copy at once.
An untested backup is not a backup
From time to time, check that your copy actually opens and that you know your master secret. That is when bad surprises show up: better on a calm day than when something fails.
03 / THE PITFALLSWhat looks like a backup but is not
A copy left next to the vault (same folder, same disk) does not protect against disk failure. Syncing between devices is not, by principle, a backup: it also copies your mistakes. QubKey offers optional sync in beta; treat it as a convenience, not your only safety net.
⚠️ False comfort
- A single copy on the same disk
- A copy never tested
- Relying on sync alone
- Master secret written nowhere, kept "in your head"
✅ Good habits
- Several copies on distinct media
- One off-site copy
- Restore tested from time to time
- Master secret kept somewhere safe, away from the device
04 / IN PRACTICEYour ten-minute routine
QubKey stores your vault locally on Windows and macOS. For the exact backup procedure of the app, refer to the product documentation when you install it.
To do this week
- Identify where your vault lives today: which device, which disk.
- Make a copy following your app's procedure and store it on a separate medium.
- Keep an off-site copy: another location, or an encrypted medium entrusted to someone you trust.
- Write down your master secret somewhere physically safe, separate from the computer.
- Test the restore on another device or in a test folder, then schedule a regular reminder.
Your data, on your device.
QubKey is a local password manager for Windows and macOS. Free during the beta.
Discover QubKey