Using Custodia
Everything the Mac app does, in the order you are likely to need it.
First launch
Set a master password of at least eight characters. Custodia shows a strength meter as you type. Write it down somewhere safe before you go any further. There is no recovery — if it is lost, so is everything you put in the vault.
Adding things
A file or folder
Click Add File or Folder and pick it from disk. The original is moved into the vault, not copied, so it leaves its old location entirely.
An app
Whole applications can go in the vault too. A vaulted app disappears from Finder and Spotlight while the vault is locked, and launches normally from inside it when unlocked. How the app was installed decides what happens next:
- Dragged into Applications by you. Moves straight in, no prompt.
- Installed by a package installer — Microsoft Teams, Office and similar. These are owned by the system, so macOS asks for an administrator password to move them. Cancel that prompt and nothing is added; the vault is left exactly as it was.
- Built into macOS, like Chess. These cannot be vaulted at all — they sit on a sealed, read-only volume that nothing can modify.
Working with what's inside
Double-click any row. Files open in their usual app, folders open in Finder, apps launch — all directly from the unlocked vault, with no copying out first.
Rename
Right-click a row, or open the Actions menu, and choose Rename… — the extension is preserved for you, so a rename can never break how an item opens or launches.
Restore, or move out
Restore puts an item back exactly where it came from. Custodia records each item's origin in an encrypted manifest inside the vault, and shows you the destination before it does anything.
If the original folder is gone, or the item predates origin tracking, use Move Out… instead and choose a new destination. Either way the item leaves the vault and becomes an ordinary file again.
Delete
The vault holds the only copy of anything in it, so deleting erases the item from your Mac entirely — nothing is written back out first. This cannot be undone.
Locking
- Press ⌘L, or click Lock.
- Closing the window locks the vault as well.
- Auto-lock waits 1, 5 or 15 minutes, or never — set it from the gear menu. The timer follows activity in Custodia itself, so working in the mounted vault through Finder does not hold it open.
If a lock fails, check whether a vaulted app is still running. Locking unmounts the volume, and a running app holds files open on it. Quit the app and lock again.
Backing up the vault
Gear menu → Back Up Vault…, then choose where to save. Custodia writes a
single AES-256 encrypted .dmg holding everything in the vault, protected by the
same master password. It is compressed and read-only, so its size follows the contents rather
than the vault's 2 TB capacity.
To restore, double-click the .dmg in Finder and enter the master password. It
mounts like any encrypted disk image — Custodia is not required — so you can
copy files out on any Mac, or add them to a fresh vault.
Worth doing before reinstalling macOS or removing the app. Keep the backup somewhere you trust: it is encrypted, but it is still a second copy, and losing the password loses it too.
Changing the master password
Gear menu → Change Password. The vault is re-keyed in place; nothing needs to be moved out and back in.
Keeping it off the screen
From the gear menu, Custodia's window title can read Workspace or Calculator instead of its own name, so a shared screen or a passing glance at the window list gives nothing away. It changes what the window is called, nothing more — there is no decoy vault and no fake contents.