Couldn't delete. Operation not permitted.Your vault and Nobody else's Vault.
Six commands.
That's the whole tool.
Everything runs through lve. Your passphrase always goes into a small prompt window, never the terminal, and every vault has its own.
Make a folder a vault. Pick a passphrase; it gets a bookmark in your Files sidebar.
Seal it. No passphrase needed: it remembers the one you unlocked with.
Open it. Asked once; the folder is back where it was.
See your vaults and whether each is open or locked.
Stop using a vault but keep the files. Unlocks first if needed.
Delete the vault and everything in it. Always asks for the passphrase.
Where your passphrase goes.
A short path, never written down, held only while the vault is open.
into a small prompt window, never the command line.
in protected memory no other program can ask for.
handed over privately; it never shows in process lists.
memory is cleared and the helper never writes crash dumps.
What a locked vault gives you
- AES-256 encryption of the whole folder in one 7z archive.
- Hidden filenames. Without the passphrase you can't tell what's inside.
- Protection from deletion. The archive is marked immutable.
- Per-user privacy. Nobody else can lock, open, or even list your vaults.
What it doesn't claim to do
- An open vault is an ordinary folder; any program running as you can read it.
- It assumes nothing malicious already runs under your account.
- Deleting the plain folder isn't secure erasure, and snapshots taken while open still contain it.
- 7-Zip doesn't keep every Linux permission, extended attribute, or SELinux label.
Forgot to lock it?
Shut down anyway.
While a vault is open, Linux-Vault holds shutdown, closes any open prompts, and locks every vault, even if a file inside is in use. Usually a couple of seconds.
A crash mid-lock leaves nothing half-done: partial files are thrown away. A vault that lost its passphrase shows as needs recovery; lock it and enter the passphrase twice.
Install.
One package; 7-Zip and the passphrase prompt come with it.
Open the package with Software, or run this from your Downloads folder:
DownloadPoint it at any folder in your home.
Coming soon A desktop app, so you won't need the terminal. Tell us what it should do →
Questions.
Where does a locked vault go?
Right beside where the folder was: ~/Example becomes ~/Example.7z. The sidebar bookmark stays and shows as missing until you unlock.
Will a system update close my open vaults?
No. Updating doesn't restart the helper, so open vaults stay open. The new version takes over at the next boot.
Why won't it lock an empty folder?
There's nothing to protect yet. Put at least one file in it (empty subfolders don't count) and try again.
Is it scriptable?
Yes. Add --json to any command for machine-readable output. Every failure has its own exit code from 1 to 15; for example 3 is a wrong passphrase and 11 is vault not found. The full table is in the README.
What if I forget my passphrase?
There's no reset and no back door. A locked vault opens only with its passphrase, so keep it somewhere safe. Each vault has its own, so forgetting one doesn't touch the others.
Can two vaults have the same name?
Not two of yours, even in different folders: lve asks you to rename one. Another user on the same computer can have a vault with the same name as yours; the two never interfere.
Can I put a vault inside another vault?
No. lve create refuses a folder that sits inside one of your vaults or has one inside it. Example and Example2 side by side are fine.
What happens if I press Ctrl-C during a lock?
lve stops, but the helper finishes the lock or unlock it already started, so the vault never ends up half-done.
What does “locked (not immutable)” mean?
The vault is locked and encrypted, but its drive doesn't support the flag that stops deletion, so the archive can still be deleted. You'll see it in lve ls.
AI agents and assistants: a plain-language summary of Linux-Vault, including what it doesn't protect against, is at lve.takethecrown.dev/llms.txt.