An independent encrypted backup and recovery path
SovaSpace separates a verified Cold Backup control package, recovery key material and large encrypted objects so each requirement is explicit.
Read the complete pageProtected spaces
Secret Spaces add separately locked areas inside SovaSpace, with their own credentials, recovery choices and stricter foreground behavior.

Standard Space is designed for the ordinary local-first workflow. A Secret Space adds an independent unlock state for material that should not remain visible merely because the main application is open.
Each Secret Space uses its own password, keys and Recovery Key. The current product can be configured with one protected space or with two independent protected spaces. A neutral help reminder is shared without identifying which protected space exists.
When SovaSpace loses focus, is minimized or the user switches to another application, the current Secret Space closes and the app returns to Standard Space. Trusted in-app pickers and viewers are handled as protected surfaces where supported.
This behavior reduces accidental exposure during task switching. It is not a defense against a compromised operating system, keylogger, screenshot tool or person controlling an already unlocked device.
A saved Recovery Key can reset the password of the corresponding Secret Space. It does not unlock every protected space and does not reveal the old password.
If no Recovery Key is available, the current design also provides a protected delayed-reset path. The waiting period gives the account holder time to notice and cancel an unauthorized reset attempt. Support cannot retrieve the original password or read the encrypted contents.
The recovery choices have different tradeoffs:
Links and backlinks are limited to Standard Space so that an ordinary knowledge graph does not reveal the existence or titles of Secret Space material. Normal background media behavior is also restricted across the protected boundary.
Exported plaintext, clipboard contents and files opened in another application follow the security of the destination environment. Secret Space protection cannot extend indefinitely into unrelated software.
Use Secret Spaces as one layer in an endpoint-security plan, not as a replacement for device encryption, operating-system account security and physical control.
Export and verify the appropriate Recovery Key, choose a neutral reminder that does not disclose the password pattern or space name, and understand the configured reset delay. A protected space is only useful when its owner can still recover it under realistic failure conditions.
Review the full feature map, current platform availability and security boundaries before choosing a workflow.