Velnode Browser · a product of Dignity New Zealand Limited
User | Version 1.1 | Last updated 2026-07-03
Document type: User Owner: Dignity New Zealand Limited Applies to: Velnode Browser v1.19 and later Last updated: 2026-07-03 Document version: 1.1 Status: Approved
This guide explains how to protect the passwords and payment cards stored in Velnode's Password Vault โ how to set up a recovery phrase, export an encrypted backup, restore on a new computer, and enable automatic local snapshots. Everything described here is local and offline; nothing leaves your device unless you choose to copy the backup file yourself.
Velnode's Password Vault uses two layers of encryption.
Layer 1 โ OS keystore. The vault file itself is encrypted by the operating system's own secure storage (Windows Credential Manager, macOS Keychain, or the Linux secret service). This means a user account that is not yours cannot read the file even if they have physical access to the drive.
Layer 2 โ Master passphrase. The passwords, card numbers, and sensitive fields inside the vault are additionally sealed with your master passphrase using AES-256-GCM + scrypt + RSA-OAEP (RSA-4096 for vaults created in v1.19 and later). This means that even someone who could extract the encrypted vault file would still need your passphrase to read its contents.
Your master passphrase is never stored anywhere, not on your device, not on any server. Velnode cannot recover it for you.
The recovery phrase is a 24-word phrase (BIP39 format) that acts as a second key to your vault. With a recovery phrase in place, you can unlock the vault if you forget your master passphrase. Without it, a forgotten master passphrase is permanent and unrecoverable.
Set up the recovery phrase before you need it โ ideally when you first create the vault.
After confirming your words, Velnode offers a PDF Emergency Kit. This is a printable document that contains:
Print the kit and store it somewhere physically secure โ a locked drawer, a fire safe, or with your other important documents. Do not store the kit only on a computer or phone, because losing the device means losing the kit.
Use this procedure if you have forgotten your master passphrase and you have your 24-word recovery phrase available.
If you enter the recovery phrase incorrectly, the vault will not open. Check your written copy carefully โ BIP39 words are exact and case-sensitive only at entry (Velnode normalises case, but spelling must be exact).
The Backup export creates a single .velora-vault file that holds all your passwords and cards, fully encrypted. You can take this file to any computer, install Velnode, and restore your vault there.
.velora-vault file โ a USB drive, cloud storage you trust, or a second device.The .velora-vault file is encrypted throughout. Its contents cannot be read without the correct passphrase (or recovery phrase, if you opted in during export). Keep the file safe; anyone with the file and the correct credential can restore your vault.
.velora-vault file.Restoring replaces the vault. Any items added to the destination vault after your last backup will be lost. Export a fresh backup before restoring on a computer that already has a vault with recent additions.
Automatic backups save an encrypted snapshot of your vault to a folder you choose, on every change. These are tied to your current computer and are intended for local rollback (recovering from accidental deletions or a corrupted vault), not for moving data between computers. Use the portable Export for that.
From this point, Velnode saves an encrypted snapshot every time your vault changes. Snapshots are named by date and time.
There is no back door. If both the master passphrase and the recovery phrase are lost, the vault cannot be unlocked by anyone, including Dignity New Zealand Limited. This is a deliberate design choice: the alternative โ a server-held recovery key โ would mean a third party can access your passwords. Velnode does not make that trade.
If you are in this situation:
This is why setting up the recovery phrase and keeping the Emergency Kit in a safe place matters.
The "Use recovery phrase" link does not appear. This option only appears after at least one failed passphrase attempt on the unlock screen. Try entering the passphrase once (even if you know it is wrong) and the link will appear.
My recovery phrase was rejected. Check spelling word by word against your written copy. BIP39 words are English and are not hyphenated. Velnode accepts upper or lower case. If the phrase still fails, it may not match the vault on this computer โ recovery phrases are bound to the vault key generated when you set them up, not transferable between different vault installations.
The restore confirmation says "no items found in backup file."
The backup file may be from an older format or from a different version of Velnode. Make sure you are on v1.19 or later. If the problem persists, e-mail [email protected] with the Velnode version shown in the title bar (or โฐ โ About Velnode).
I forgot whether I enabled the recovery-phrase option when I exported.
Try restoring with your master passphrase first. If that fails, try the recovery phrase. There is no way to inspect a .velora-vault file to determine which credentials it accepts without attempting a restore.
Automatic backups stopped saving. Check that the chosen folder still exists and is writable. If you moved the folder or the drive is disconnected, Velnode will silently skip the backup rather than crash. Reopen the automatic backup settings, re-choose the folder, and save.
.velora-vault export file are the user's responsibility. Store both carefully. Treat them like a copy of your house key.Document maintained by Dignity New Zealand Limited. Questions: [email protected].