A backup answers “Can we restore stored records?” A Recovery Key answers “Can the owner unlock protected records?” Conflating the two creates dangerous promises: either that support can recover a secret it never held, or that encryption protects data from deletion and operational failure.
Two recovery questions
Confidentiality, availability, and recoverability are related but separate. An attacker copying stored records should not receive their protected plaintext. A disk failure should not erase the only copy of those stored records. A person who loses every unlock secret should not be told that a server can recreate the key it was designed not to hold.
What a backup can preserve
A recovery set can include database records, encrypted Master Keys, vault parameters, attachments, and the opaque ciphertext stored for Protected Memories. Restoring those artifacts can make the account state available again. It does not by itself make protected writing readable: the restored browser still needs a valid user-held unlock route.
What a Recovery Key can preserve
The Recovery Key provides an alternative way for the owner to unlock the Master Key after losing the Vault Password. It is exported in the browser and is not received by the server. It cannot restore a deleted Memory, a missing blob, or an unavailable database. Read how Recovery Keys work without server key access for the cryptographic boundary.
Why this is not key escrow
Key escrow gives an operator a route to decrypt user content. Inpages' recovery design instead gives that alternative route to the owner. This means support cannot override the loss of both the Vault Password and Recovery Key. That is difficult in a support conversation, but it is consistent with saying the server does not hold the usable Master Key.
A restore drill is evidence
A script that produces an encrypted archive is useful, but it is not enough evidence to call disaster recovery complete. The current backup runbook explicitly says the process is not operationally proven until a full restore drill succeeds, including a controlled login, protected Memory unlock, and encrypted attachment read. A backup claim should match that evidence level.
How to communicate the boundary
Say exactly what is preserved, who can unlock it, where the recovery artifact lives, and which restore evidence exists today. The LastPass breach case study shows why copied backups and a lost secret are different risks. Precise language helps people prepare for both.