Skip to main content

SEC-004 โ€” Credential Backup & Recovery

Document: SEC-004Type: StandardStatus: ApprovedOwner: Cloudberrie LeadershipVersion: 4.2.0Updated: 2026-07-17

Recovery Objectiveโ€‹

Cloudberrie must be able to recover access to critical infrastructure if the primary Mac, browser session, authenticator, or administrator is unavailable.

Required Copiesโ€‹

CopyLocationContents
PrimaryApple PasswordsCredential, account identity, recovery codes and notes
SecondaryEncrypted offline storage in a physically secure locationTier 1 recovery codes and emergency ownership references
Not permittedEmail, unencrypted cloud drive, screenshots or chatAny usable secret

Recovery Testโ€‹

At least annually, and after major account changes, verify:

The protected entry can be opened Recovery codes are still valid or have been refreshed The authorized owner can identify the correct login URL The offline recovery copy is readable and secure

Emergency Sequenceโ€‹

  1. Use the official platform recovery process.
  2. Verify the legal and operational owner before changing access.
  3. Reset the password and MFA factors.
  4. Revoke unknown sessions and tokens.
  5. Document the event without recording secrets in the manual.
  6. Replace stored recovery codes after use.