Protected spaces

Secret Spaces for more sensitive work

Secret Spaces add separately locked areas inside SovaSpace, with their own credentials, recovery choices and stricter foreground behavior.

A boundary inside the workspace

Standard Space is designed for the ordinary local-first workflow. A Secret Space adds an independent unlock state for material that should not remain visible merely because the main application is open.

Each Secret Space uses its own password, keys and Recovery Key. The current product can be configured with one protected space or with two independent protected spaces. A neutral help reminder is shared without identifying which protected space exists.

Automatic privacy exit

When SovaSpace loses focus, is minimized or the user switches to another application, the current Secret Space closes and the app returns to Standard Space. Trusted in-app pickers and viewers are handled as protected surfaces where supported.

This behavior reduces accidental exposure during task switching. It is not a defense against a compromised operating system, keylogger, screenshot tool or person controlling an already unlocked device.

Recovery Key and delayed reset

A saved Recovery Key can reset the password of the corresponding Secret Space. It does not unlock every protected space and does not reveal the old password.

If no Recovery Key is available, the current design also provides a protected delayed-reset path. The waiting period gives the account holder time to notice and cancel an unauthorized reset attempt. Support cannot retrieve the original password or read the encrypted contents.

The recovery choices have different tradeoffs:

  • Recovery Key: immediate when the correct key is available; requires the user to store it safely.
  • Delayed reset: does not require the Recovery Key; intentionally cannot complete immediately.
  • No recovery material: can make protected content permanently inaccessible.

Deliberate limitations

Links and backlinks are limited to Standard Space so that an ordinary knowledge graph does not reveal the existence or titles of Secret Space material. Normal background media behavior is also restricted across the protected boundary.

Exported plaintext, clipboard contents and files opened in another application follow the security of the destination environment. Secret Space protection cannot extend indefinitely into unrelated software.

Use Secret Spaces as one layer in an endpoint-security plan, not as a replacement for device encryption, operating-system account security and physical control.

Set recovery before storing critical material

Export and verify the appropriate Recovery Key, choose a neutral reminder that does not disclose the password pattern or space name, and understand the configured reset delay. A protected space is only useful when its owner can still recover it under realistic failure conditions.

See how the complete workspace fits together.

Review the full feature map, current platform availability and security boundaries before choosing a workflow.