Practice Vault is an optional security feature that gives you an extra layer of protection over your most sensitive clinical data. When enabled, your records are secured with a personal passphrase that only you know — the highest level of protection our platform offers.
What's protected
Once Practice Vault is enabled, the following are secured with your personal passphrase:
- Session notes
- Client documents and intake form submissions
- Sensitive client profile information
How it works
When you set up Practice Vault, you create a personal passphrase — a memorable phrase that only you know. This passphrase is used to secure your records directly in your browser, so your data is protected before it ever reaches our servers.
During setup, you'll also be given a 24-word recovery key — a unique backup in case you ever forget your passphrase.
Once set up, your vault unlocks automatically on devices you trust. On a new or unrecognised device, you'll be prompted to enter your passphrase to gain access.
Setting it up
- Go to Settings → Security.
- Click Set up Practice Vault.
- Choose a strong, memorable passphrase and confirm it. A passphrase strength indicator will help you choose a secure phrase.
- Write down or securely save your 24-word recovery key. Check the confirmation box to confirm you've stored it safely.
- Click Finish setup. Your existing records will then be secured — keep the window open while this runs, as it may take a few minutes depending on how many clients you have.
Using Practice Vault day to day
Once your vault is set up, it works quietly in the background. A shield icon in the top right of your browser shows whether your vault is active on that device.
On a device where your vault is unlocked, everything appears as normal. On a new or locked device, you'll see a prompt to enter your passphrase — your records remain hidden until you do.
New data — such as incoming intake form submissions — will appear as pending and prompt you to add them to your vault. You can do this immediately or later, in which case a reminder will persist in your Client Center until it's secured.
Managing registered devices
Once you unlock your vault on a device, that device is registered and will unlock automatically on future visits. You can view and manage all registered devices from Settings → Security → Manage devices.
If you no longer use a device — or suspect it's been compromised — you can revoke its access. That device will then require your passphrase to unlock the vault again. You can re-register it at any time by entering your passphrase on that device.
Recovering access
If you forget your passphrase, you can recover access using your 24-word recovery key. Go to Settings → Security and select Forgot passphrase? You'll be prompted to enter your recovery key and set a new passphrase.
If you've lost both your passphrase and recovery key but still have an active unlocked device, you can disable Practice Vault from that device to restore access to your data. See Disabling Practice Vault below.
Disabling Practice Vault
You can disable Practice Vault at any time from Settings → Security. Your vault must be unlocked to do this. Once disabled, your records are moved back to It's Complicated's standard security infrastructure — they remain encrypted and safe, just without the additional passphrase protection.
Disabling Practice Vault is a deliberate process and will ask for your confirmation before proceeding.