Storage Integrations (BYOS)
Bring Your Own Storage (BYOS) is one of Eternal Vault’s most powerful features. Instead of uploading files to our servers, you can connect your existing cloud storage services like Google Drive, and your files stay exactly where they are. We just create secure links to them.
While storage integrations are convenient, we recommend uploading sensitive documents directly to Eternal Vault for maximum security. Direct uploads are encrypted with client-side encryption before storage, ensuring only you and your trusted contacts can access them. With storage integrations, security depends on your cloud provider’s policies.
What is BYOS?
Your Files Stay Put
- Documents remain in your Google Drive, Dropbox, OneDrive, etc.
- Never imported to Eternal Vault’s servers
- Always under your control in your own storage accounts
Secure Connections Only
- We only access files you explicitly choose through the file picker
- No browsing your entire storage - you pick each document individually
- Encrypted access tokens stored securely on our servers
- Disconnect anytime and remove all access instantly
Perfect for Privacy
- Maximum privacy: Your files never leave your storage
- GDPR compliant: Your data stays in your preferred location
- Audit trail: See exactly which files are connected
- Emergency access: Still works with trusted contacts when needed
Getting Started with Storage Integrations
Step 1: Access Storage Integrations
- Log into your dashboard at dash.eternalvault.app
- Navigate to Integrations in the sidebar
- Click “Storage” to see available integrations
Step 2: Choose Your Storage Service
Currently available:
- Google Drive
- Dropbox
- Box
- S3-Compatible Storage - Garage, MinIO, Ceph, Cloudflare R2, Backblaze B2, Wasabi, DigitalOcean Spaces, Amazon S3
- OneDrive (Planned)
Step 3: Connect External Storage
For Google Drive, Dropbox and Box:
- Click “Connect” on the external storage card (For example, Google Drive)
- You’ll be redirected to Google’s authorization page
- Sign in to your Google account (if not already signed in)
- Review permissions that Eternal Vault is requesting
- Click “Allow” to authorize the connection
For S3-Compatible Storage, there is no sign-in step. You provide the connection details yourself:
- Click “Connect” on the S3-Compatible Storage card
- Pick your provider from the list to prefill the endpoint and region
- Enter your bucket, and optionally a folder prefix to limit us to one part of it
- Paste a read-only access key and secret
- Click “Test connection” to confirm it works, then “Connect”
Eternal Vault only ever reads from your bucket, so give it a key that can only read. The connect dialog shows the exact commands or console steps for your provider. A folder prefix limits us further, to just the part of the bucket you choose.
Step 4: Confirm Connection
After authorization, you’ll be redirected back to Eternal Vault where you’ll see:
- Success notification confirming the connection
- Updated status showing “Connected” with a green badge
- Last checked timestamp for health monitoring
Adding Documents from Your Storage
- Go to Documents section in your dashboard
- Click “Add Document” dropdown arrow
- Select your connected storage (e.g., Google Drive)
- Use the file picker to choose specific documents
The Google Drive file picker allows you to:
- Browse your Drive in a familiar interface
- Search for specific files using Google’s search
- See file previews and details
- Filter by file type (documents, images, PDFs, etc.)
- Select exactly the file you want to connect
Once you select a file:
- Add title and description for your vault
- Choose categories and tags for organization
- Select which vault to add it to
- Click “Connect Document” to finalize
How Security Works
File Access Levels
During Normal Operations:
- Files remain private in your storage
- Only you can access them through Eternal Vault
- No public links are created
During Emergency Access:
- Files stay private in your storage - nothing is ever shared publicly
- Trusted contacts download through Eternal Vault, which fetches the file for them
- Access ends immediately if you send a heartbeat (false alarm)
Managing Your Integrations
Connection Status
Your storage integrations show simple status indicators:
- Status indicators show current state:
- Connected: Integration is active and working
- Not Connected: Ready to be connected
- Coming Soon: Integration not yet available
Disconnecting a Service
To disconnect a storage integration:
- Click “Disconnect” on the integration card
- Confirm the disconnection in the dialog
- Access is immediately revoked from our side
- Files remain in your storage but are no longer linked
Important: Disconnecting will make connected documents inaccessible through Eternal Vault, including during emergency access.
Emergency Access with BYOS
How It Works
When your inactivity threshold is exceeded and your trusted contacts open the vault, connected documents are served through Eternal Vault. We fetch each file from your storage on request and hand it to the contact who is opening the vault.
Your contacts never need an account with Google, Dropbox, Box or your S3 provider, and your files are never made public to make this work.
Security & Privacy Protection
- Nothing is shared publicly: We do not change permissions on your files or create public links
- Access is tied to the vault: Only contacts who have successfully opened the vault can retrieve documents
- Fetched on demand: Files are never copied to our servers, they are passed through when requested
- Immediate revocation: Access stops the moment you send a heartbeat (false alarm recovery)
What Contacts See
Your trusted contacts will see external documents like this:
- Document name and description you provided
- Storage source (e.g., “Google Drive”)
- View or download the file directly from the vault, the same as any other document
Frequently Asked Questions
Can Eternal Vault see all my files?
No. We only have access to files you explicitly select through our file picker. We cannot browse your entire Google Drive or other storage services. The OAuth permissions we request are limited to individual file access only.
Are my files encrypted with storage integrations?
No - this is important to understand. Files connected through storage integrations remain in your cloud storage with whatever encryption and security your storage provider offers. For maximum security, we recommend uploading sensitive documents directly to Eternal Vault where they are encrypted with client-side encryption before storage. Only you and your trusted contacts can decrypt directly uploaded files.
What happens to my files if I cancel my subscription?
Your files remain safe in your own storage services. They’re not dependent on Eternal Vault. However, you’ll lose the ability to:
- Connect new documents from storage
- Provide emergency access to connected documents
- Use the file picker integration
Can I change which files are connected?
Yes. You can:
- Add new files anytime using the file picker
- Remove documents from your vault (doesn’t delete from your storage)
- Update document details like titles and descriptions
- Change categorization and tags
What happens if I change my storage password?
OAuth tokens are separate from your storage password. Changing your password won’t affect the connection. However, if you revoke Eternal Vault’s access from within your Google/Dropbox settings, you’ll need to reconnect.
How often does Eternal Vault check my storage?
- Health checks: Every few hours to verify connection status
- File verification: Only when accessing documents
Can I use multiple storage services?
Yes! You can connect multiple services:
- Google Drive + Dropbox + Box + S3-Compatible Storage
- Different files from different services
- Manage all connections from one dashboard
- Emergency access works across all connected services
Troubleshooting
Connection Issues
“Failed to connect storage”
- Check your internet connection
- Try again - temporary Google API issues happen
- Use incognito mode to avoid browser conflicts
- Check popup blockers - OAuth needs new windows
“Permission denied”
- Check Google account access - some organizations restrict OAuth
- Try personal Google account if using work/school account
- Clear browser cookies for accounts.google.com
- Contact support if organization policies block access
File Access Issues
“File not found” during emergency access
- File may be moved in Google Drive after connection
- File may be deleted from storage
- Permissions changed on the original file
- Storage account deactivated
“Cannot reach your storage”
- Endpoint or bucket may be wrong for an S3 connection
- Credentials may have been rotated or their permissions changed
- Storage service may be temporarily unreachable
- Organization policies might block access from outside your network
Health Check Failures
“Integration needs attention”
- Token may be expired - try disconnecting and reconnecting
- Storage service may be temporarily down
- Account changes in your Google/Dropbox account
- API limits may be temporarily hit
Ready to connect your storage? Head to your Storage Integrations page and get started with BYOS today.
Questions? Contact our support team for help with storage integrations.