User Guide

Setting up account security

A walkthrough of how new accounts get protected in DynoLocker; from your first login to unlocking folders and recovering your settings on a new device.

1
Required every session

Enter your encryption key

Before you can do anything else in DynoLocker, you'll need the encryption key your business admin issued you. This unlocks your encrypted credentials for the current session only.

1
Wait for the session unlock promptThis appears automatically before you can access anything else, with two tabs: "Enter key" and "Restore from Google Drive".
2
Enter the key from your business adminOn the "Enter key" tab, type the encryption key your business admin gave you into the Encryption key field.
3
Or restore it from Google DriveIf cloud backup has been turned on for this account (see Step 6), switch to the "Restore from Google Drive" tab instead of typing the key manually.
4
Select "Unlock Session"Once verified, your credentials are decrypted for this session and you're dropped into your dashboard.

Encrypted locally

Credentials never leave your device unencrypted.

Non-recoverable

Lost keys can't be reset by support, keep it somewhere safe or turn on cloud backup once you're in (Step 6).

2
Required for every account

Enable Two-Factor Authentication

On first login, DynoLocker blocks access until 2FA is turned on. This keeps every folder protected by more than just a password.

Security requirement

New accounts see a locked screen reading "You must enable 2FA to proceed." Nothing else is usable until this step is complete.

Encryption key comes first

If your business encryption key hasn't been generated yet, DynoLocker will ask you to finish that in Business Settings before 2FA can be enabled — trying to enable 2FA early returns "MFA/2FA is not enabled for this account" until the key is set and verified.

1
Go to Business SettingsGenerate and verify your encryption key. This unlocks the 2FA setup flow.
2
Open Settings → SecurityYou'll see "Two-Factor Authentication is OFF" with a summary of why it matters: stronger security, app-based OTP, and backup codes.
3
Select "Enable Two-Factor Authentication"A setup panel opens with three steps: Scan QR Code, Verify Code, Save Backups.
4
Scan the QR codeUse Google Authenticator, Microsoft Authenticator, or Authy. No app handy? Copy the manual entry code shown below the QR code instead.
5
Enter the 6-digit OTPConfirm the code your authenticator app generated to verify the pairing.
6
Save your backup recovery codesDownload or copy the five one-time codes shown. They're only displayed once — store them somewhere safe.

2FA Activated Successfully

Once verified, your account is protected with two-factor authentication and the security banner clears from your dashboard.

3
Optional, but faster

Register a passkey

Passkeys let you unlock folders with your device's biometrics - Face ID, Touch ID, or Windows Hello, instead of typing a 6-digit code every time.

1
Open Settings → PasskeysThis screen lists any passkeys already registered on your account.
2
Select "Add passkey"You'll be asked to confirm your identity first.
3
Enter your 6-digit authenticator codeOne-time confirmation that it's really you registering the new passkey.
4
Approve the device promptYour browser/OS (Windows Hello, Face ID, Touch ID, or a hardware security key) asks you to save the passkey, e.g. entering your Windows PIN.

What this changes

Once registered, the folder-unlock prompt offers a "Passkey" tab alongside the authenticator code — pick whichever is faster on the device you're using.

4
Every time you open a folder

Unlocking a folder

Locked folders stay locked until you verify with one of your two registered methods. Unlocked folders limit is for 30 minutes and then gets locked after the duration.

Locked folder selected
Verification prompt appears
1
Click into any locked folderA "Two-Factor Authentication" dialog appears with two tabs: Authenticator code and Passkey.
2
Choose your methodType the current 6-digit code from your authenticator app, or switch to the Passkey tab and approve with biometrics.
3
Select VerifyThe folder unlocks for your session.

Lost access to your authenticator?

Use one of the backup recovery codes you saved during Step 2 to regain access, then re-register a new authenticator app.

5
Sharing outside your account

Secure Share

Secure Share lets you send a credential or folder to someone else through a password-protected, end-to-end encrypted link — without giving them access inside DynoLocker itself.

1
Select "Secure Share" on the item you want to sendA three-step dialog opens: Password, Confirm, Share.
2
Choose a strong encryption passwordThis password encrypts the link's contents before anything leaves your device — it is never sent to DynoLocker's servers.
3
Pick a link typeChoose "One-time" if the link should expire after it is opened once, or "Time-bound" if it should expire after a set duration instead.
4
Add an optional messageInclude any context the recipient needs alongside the shared item.
5
Select "Continue" to generate the linkYou'll land on the "Link ready to share" screen with the shareable URL and its expiry date and time.
6
Send the link and password separatelyCopy the link and hand it to your recipient through one channel, then send the encryption password through a different channel.

One-time link

A one-time link expires after its first open. Always send the link and password via separate channels.

Encrypted end-to-end

Shared content is AES-256 encrypted, and your password is never sent to DynoLocker's servers.

One-time

Expires after first open.

Time-bound

Expires after a set duration.

6
Optional

Cloud backup & restore

Back up your encrypted recovery key so you can pick up on a new device without re-entering your recovery phrase.

Back up to Google Drive

Saves your encrypted recovery key to a hidden, app-private folder in your Google Drive. It's protected the same way it is on this device.

Restore from Google Drive

On a new device, restore from that backup to bring back the same account settings — no need to re-type your recovery phrase.

Convenience backup, not third party access

This is protected the same way your data is on-device. Keep your recovery phrase as the ultimate fallback. DynoLocker only uses the DynoLocker only accesses its own isolated folder inside your Google Drive , so it never gets access to the rest of your Drive.

AES-256-GCMZero-knowledgeWebAuthn / Passkey
7
What you can do depends on your access

Understanding your permissions

Your admin decides what you can do inside each folder by granting a combination of Read, Create, Update, and Delete — either directly, or through a role assigned to you. What you see in the app matches exactly what you've been given.

Read

View folders and open credentials you've been given access to.

Create

Add new folders or credentials inside folders you have this permission on.

Update

Edit existing folder details or credential values.

Delete

Move a folder or credential to Trash.

1
Check what a folder or credential lets you doAvailable actions (e.g. Create, Edit, Delete buttons) only appear for the folders where your admin has granted them — if an action isn't visible, you don't currently have that permission.
2
Permissions can come from a roleIf your admin assigned you a role, your access to folders and actions matches whatever that role was configured with, and updates automatically if the role changes.
3
Or permissions can be set manually for youYour admin may instead have checked off specific folders and actions just for your account, separate from any role.
4
Need broader access?Ask your admin to update your role or your individual folder permissions — you won't be able to change this yourself.

Same account, different access

Two people on the same team can see completely different sets of folders and actions this is expected, and reflects what each person's admin has granted them.

Start protecting your credentials today

Set up your encrypted vault in minutes. Your data is encrypted on your device before it ever reaches us — that's a promise backed by math, not policy.