Holos Drive Vault app icon
Coming soon · Encrypted Drive Security

Holos Drive Vault

A security-first utility for creating encrypted macOS APFS external drives that can work across Mac and Windows environments. Holos Drive Vault prepares the secure APFS vault on macOS, stores recovery material in OS-managed keychains, and keeps drive access under your control without a DeadStick account, analytics profile, or recovery-key server.

Overview

Holos Drive Vault is the drive-provisioning tool in the Holos family: a macOS app for turning eligible external disks into APFS-encrypted vaults that can move into a Windows workflow. It enumerates external drives, makes the destructive-format step explicit, creates a small setup partition for handoff, and builds the encrypted APFS volume behind a PIN or password you choose.

The companion recovery flow is designed around the platform security model. Recovery keys are stored in Apple Keychain, can sync through the user's own iCloud Keychain when enabled, and can be revealed only after Touch ID, Face ID, or device passcode authentication succeeds. DeadStick Digital does not receive or escrow the key.

What it does

  • Discovers external macOS drives and avoids internal startup-disk operations.
  • Runs a guided setup flow for contact details, PIN or password selection, and final confirmation before formatting.
  • Creates an encrypted APFS vault volume on a selected external drive from macOS.
  • Prepares the drive for a Windows-side access path through companion tooling while keeping the encrypted vault boundary intact.
  • Stores recovery material in the OS keychain instead of a DeadStick-operated database.
  • Uses Touch ID, Face ID, or device passcode before displaying a synced recovery key on a trusted Apple device.
  • Includes a local-first Windows path through Windows Credential Manager and a user-mode APFS bridge, without a DeadStick key server.

How your data is protected

Holos Drive Vault is built around a narrow data path: the encrypted drive, your device keychain, and optional iCloud Keychain sync that you control in system settings. The app does not create a web account and does not upload drive contents, PINs, recovery keys, or usage telemetry to DeadStick Digital.

If you add recovery contact details, those details are written to the drive's setup partition so someone who finds the drive can contact you. That file is intentionally visible on the drive; only include contact information you are comfortable putting on the removable media itself.

Why Holos Drive Vault is safe and secure

Security is the point of the app, not a feature added later. The design favors operating system protections, local storage, explicit user consent, and recoverability without handing DeadStick Digital a copy of your secret material.

  • No DeadStick recovery-key server. DeadStick Digital does not receive, store, sell, share, or recover your drive PIN, password, or keychain item.
  • OS-backed key storage. Recovery material is stored through Apple Keychain and, when you enable it, iCloud Keychain rather than an app database.
  • Biometric data stays on device. Touch ID and Face ID are handled by the operating system; Holos Drive Vault receives only the success or failure result.
  • Local-first drive encryption. External-drive setup creates a macOS APFS encrypted vault volume, with your chosen PIN or password protecting the files.
  • Mac-created, Windows-usable design. The drive is prepared on macOS and designed for Windows access through local companion tooling rather than a remote DeadStick unlock service.
  • External-drive safety checks. The macOS app filters for external disks, avoids the internal startup disk, and requires confirmation before destructive formatting begins.
  • No accounts, ads, or telemetry. The app is designed without user accounts, advertising SDKs, behavioral analytics, or app-usage tracking.
  • User-controlled sync boundary. Key sync, when available, uses the user's own iCloud Keychain setting; turning off iCloud Keychain keeps keys local to the device.
  • Clear deletion path. Removing the app, erasing the drive, and deleting related keychain or credential-manager entries removes the copies under your control; there is no DeadStick server-side account to delete.

Privacy and store disclosures

For Apple App Store and Google Play review, Holos Drive Vault is documented as an app that does not collect or share user data with DeadStick Digital. Any recovery contact information you choose to write belongs on the drive itself, and any iCloud Keychain sync is handled by Apple under the Apple account and system settings you control. See the privacy policy, support page, and data deletion page for the public URLs required by store listings.

Important safety note

Formatting a drive deletes data on that drive. Holos Drive Vault is for drives you own or are authorized to manage, and it is not a data recovery service. Keep backups of anything important before setup, and keep your recovery information safe; DeadStick Digital cannot recover encrypted drive contents if your device, keychain, and backups are lost.

Platforms

Coming soon: macOS 14 or later to create encrypted APFS external drives; iOS companion for key recovery through iCloud Keychain.
Planned: Windows companion components for APFS mounted-drive access. Android support will be documented separately if it ships.