I use Bitwarden to organize my online accounts, physical security keys to protect sign-ins, and separate email addresses for personal and business services. I store files locally and back them up to a NAS and an external hard drive.
I also ask questions before giving a service access to my information. That applies to the tools I use personally and the services I assess for clients through Entori.
1. I review providers and ask questions
Before connecting an app or AI tool to email, files, or another service, I review the permissions it requests. I read its privacy and data retention terms, security documentation, available independent audits, and company history. I contact the company when I have questions.
A client wanted to use Wispr Flow. I asked the company about its zero-retention policy and how that worked in practice, including storage and processing. They answered my questions and were transparent in their explanation.
When reviewing a service, check what it can read, change, or send. Ask where your information is processed, what is retained, for how long, and which settings control that behavior.
Check the current settings. Wispr’s data controls distinguish model improvement from dictation cloud storage. Transcription still takes place in the cloud. Review both controls when assessing the service.
2. I keep my logins in Bitwarden
Bitwarden is my password manager and account inventory. I organize entries into folders and use it to generate and save unique passwords.
I protect Bitwarden itself with a physical security key for two-factor authentication. A security key is a small device used to verify your identity during sign-in.
I have Bitwarden set to log out after one minute of inactivity within Bitwarden. That is the timeout I use for my setup.
Bitwarden’s timeout settings include separate options to lock the vault or log out. Check the action as well as the time interval in each Bitwarden app you use.
3. I use passkeys and keep recovery options
Where a service supports it, I use a passkey stored on a physical security key. Passkeys use cryptographic credentials tied to the service you are signing in to. They replace the shared password used in a conventional password sign-in.
I have multiple physical keys. My backup arrangements vary by service: some have an authenticator app available as another sign-in method; others have recovery codes that I keep on paper.
When setting up an account, check its recovery options alongside its sign-in settings. Record how you would regain access if your usual authentication method became unavailable. Where supported, register a spare security key and test it.
4. I use several email addresses
I use Proton Mail for personal email, including additional addresses for signups where I expect unwanted mail. I also have my Entori business email and other personal and business addresses.
When registering for a service, I choose which address to use. My account entries in Bitwarden record the login details.
5. I configure my browser and devices
I use Brave for most browsing, with Privacy Badger, uBlock Origin Lite, and Bitwarden. I don’t use the browser’s built-in autofill.
Full-disk encryption is enabled on all the computers where I store files. I also have automatic operating-system and security updates enabled.
6. I decline the option to save payment details
When paying online, I enter my card details and decline the merchant’s option to save them for future purchases.
I keep my card details in Bitwarden, with an additional prompt configured for those entries.
Bitwarden’s master-password re-prompt adds a check within the app. It does not separately encrypt the item or replace logging out of an unattended vault.
7. I store files locally and test my backups
I store my files locally and back them up to a NAS, a storage device on my network, and an external USB hard drive. I disconnect the USB drive between backups and keep it in a safe place.
Restore from each destination. Open the recovered file and check its contents.
Include a restore test when checking your own backup arrangements. Restore a file from each destination and confirm that you can open it.
Keep at least one backup in a separate location. The NCSC’s backup guidance covers offline copies, separate storage, and regular restore tests.
8. I have an emergency-access arrangement
I use Bitwarden’s Emergency Access feature. It allows a designated trusted person to request access to my vault under the arrangement I configure. I also keep additional codes in offline storage.
When configuring Emergency Access, review the access level and waiting period, and complete the trusted-contact setup. Adding a trusted contact requires Bitwarden Premium access; the contact can use a free Bitwarden account.
9. I review changes and close unused accounts
Security alerts, new features, and updated permissions prompt me to review services I already use. I revisit the settings and access relevant to the change.
When I stop using a service, I close the account.
CHECK YOUR SETUP
Three checks to make on your own setup
- Review your accounts.List the online accounts you use and identify any you can close.
- Check account recovery.Review the recovery options for your primary email and password manager.
- Restore a file.Restore a file from each backup destination and confirm that you can open it.

