Digital Legacy and Cybersecurity: Preparing Access Without Weakening Security
Written by Daniel Tanguay, founder of Solexi.ai.
Every security control that protects an account while you are alive — a strong password, a second factor, a locked device, a recovery phone number — is also what stands between your family and that account afterwards. Preparing digital continuity means solving both problems at once, not trading one for the other.
Why password sharing is not enough
The instinctive answer is to write the passwords down and leave the list somewhere safe. It fails for three separate reasons. The list goes stale the moment a password is rotated. It is a single point of catastrophic failure if it is found, photographed or copied. And it does not survive the controls that sit on top of the password.
A credential is only one part of the access chain. Modern accounts also check the device, the session, the location and a second factor. A relative holding a correct password can still be refused at every one of those checkpoints, and repeated failed attempts often trigger a lockout that makes the situation worse.
- Passwords change; a written list silently becomes wrong.
- A shared list weakens security today for a benefit that may never arrive.
- A correct password is frequently not sufficient to complete a sign-in.
- Failed attempts can lock the account exactly when it is needed most.
The problem with multi-factor authentication
Multi-factor authentication is the right default and should stay switched on. But its second factor is usually bound to something physical: a phone number, an authenticator app on one device, a hardware key in a drawer, or biometrics that cannot be reproduced. If nobody knows which factor protects which account, or where the factor physically lives, the account is effectively sealed.
The most common blocking pattern is circular. The email account holds the recovery links for everything else, the email account is protected by a code sent to a phone, the phone is protected by a passcode nobody knows, and the phone carrier will not transfer the line without documents that take weeks to obtain.
- SMS codes depend on an active line and an unlocked handset.
- Authenticator apps are usually installed on a single device.
- Hardware keys are useless if the family does not know they exist.
- Biometric factors cannot be delegated at all.
Devices and account recovery
Devices are the quiet centre of the problem. A laptop passcode, a phone lock screen and full-disk encryption are all doing their job when they refuse an unknown person. Recovery keys for encrypted drives, printed backup codes and the answers to old security questions are the documented escape hatches, and they are exactly the items nobody writes down.
Recovery is also provider-specific. Each platform publishes its own process for a deceased or incapacitated user, with its own proof requirements and its own outcome, ranging from full data export to memorialization to closure only. Knowing in advance which platforms matter to you shortens that work considerably.
- Record which devices exist and who can physically reach them.
- Store encryption recovery keys and printed backup codes deliberately.
- Note which accounts depend on which email address and phone number.
- Check what each important provider actually offers before it is needed.
Trusted contacts
Several major platforms now let a person nominate someone in advance — a legacy contact, an inactive account manager, or an equivalent role. These built-in mechanisms are the safest path available, because they grant access through the provider rather than around it, and they can be configured today without handing over any credential.
They are also partial. They cover the platforms that offer them, at the level of access those platforms decide, and they do nothing for the bank, the utility, the professional archive or the encrypted drive. A trusted-contact strategy has to be assembled account by account.
Preparing future access safely
The goal is not to distribute secrets. It is to remove uncertainty, so that a person with legitimate authority can follow a documented path instead of guessing. That distinction is what keeps a continuity plan from becoming a security liability.
- Prefer provider-native mechanisms over any private password hand-off.
- Keep the map (what exists, where, who to contact) separate from the secrets.
- Name who is allowed to act, and say what they are allowed to do.
- Review after any phone change, email change or new second factor.
- Never store a plaintext password list in a shared drive or a note app.
What families should document
When families are asked afterwards what would have helped, the answer is almost never “more passwords”. It is a list of what exists and who to contact.
- Which email addresses are in use, and which is the recovery address.
- Which accounts hold money, subscriptions or ongoing obligations.
- Where photos and family memories are actually stored.
- Which devices exist, and whether anything exists only on one of them.
- Any cryptocurrency holdings and how they are custodied.
- Which professionals (notary, lawyer, advisor, accountant) are involved.
- What the person wanted kept private, deleted or preserved.
How digital continuity differs from password storage
A password manager answers “what is the credential?”. Digital continuity answers “what exists, why it matters, who may act, and what should happen”. The two are complementary, and neither replaces the other. A vault full of credentials with no context still leaves a family reading a list of service names they do not recognise.
Solexi.ai is being built for the second question: organizing the map, the documents, the memories and the instructions, so that the security controls can stay exactly as strong as they are today.
Independent coverage of the same problem
This is not a niche concern invented by software vendors. In an August 2026 episode, the Shared Security Podcast examined what happens to accounts, passwords, devices, files, cloud storage, cryptocurrency and online identity after a death, and the practical dependencies — recovery chains and multi-factor authentication — that decide whether anyone can act. We link to the original episode rather than reproducing it.
Independent research and professional publications are examining many of the same problems Solexi.ai is being built to address. That is context, not endorsement.
Pricing, in plain words
- 14 days free, 1 GB included during the trial
- Then CAD $199, one time only
- Lifetime access, 10 GB included
- No monthly subscription, no renewal
Frequently asked questions
Should I disable MFA so my family can get in?
No. Disabling multi-factor authentication weakens the account immediately in exchange for a hypothetical future benefit. Use provider-native legacy or trusted-contact features, and document which factor protects which account instead.
Is a sealed envelope of passwords a reasonable backup?
It is better than nothing and worse than a plan. It goes out of date, it can be found, and it usually does not defeat second factors or device locks. If you keep one, treat it as a supplement to a documented map, not as the plan itself.
What is the single most useful thing to prepare first?
The primary email account. It is the recovery channel for nearly everything else, so documenting how it is protected and who is nominated on it unlocks the largest share of the problem.
Sources & Further Reading
The organizations, researchers and professionals referenced on this page do not necessarily endorse, partner with or have any relationship with Solexi.ai. They are cited as independent sources documenting issues related to digital legacy and continuity.
- What Happens to Your Digital Life When You Die? — Shared Security Podcast
Shared Security Podcast — Tom Eston — Published 2026-08-24 — Last verified : 2026-08-26
https://sharedsecurity.net/2026/08/24/what-happens-to-your-digital-life-when-you-die/
Last reviewed : 2026-08-26
Solexi does not replace a legal will, a notary or a lawyer. Solexi helps you gather, organize and pass on your information.