Why won't the vault open on a rooted phone?

Published By Stillgarth3 min read

The vault won’t open on a phone that looks rooted because root breaks the protection the vault depends on. Android normally walls each app off, so no other app can read its private storage or its memory. On a rooted phone, anything that has been given root can reach past those walls, including into the vault while it’s open. Rather than give you a false sense of safety, Stillgarth refuses to open the vault there. Home and Phone Guard still work.

What does “rooted” mean?

Rooting a phone gives apps and tools full control of the system, beyond what Android normally allows any app. People root phones to customise them or remove software they don’t want. The trade-off is that the rules keeping apps apart no longer hold for anything that gets root access.

Why does root matter for a vault?

The vault’s protection has two parts:

  • At rest, everything is encrypted: every file with AES-256-GCM, the names and folders in an encrypted database, and the key that opens them only in locked form. Root doesn’t change that.
  • While the vault is open, the key that decrypts your files is in the app’s memory, and the files you view are decrypted in memory too. Android’s walls between apps are what keep everything else out of that memory and out of the app’s private storage.

On a rooted phone, a tool with root could read that memory, get around the screenshot block, or watch what you type. Encryption is only as strong as the place where it’s unlocked.

What does Stillgarth check for?

Before the vault opens, Stillgarth looks for signs that the phone has been rooted or modified, that a debugger is attached, or that an instrumentation tool (such as Frida, which can inspect and change running apps) is present.

If it finds them, you’ll see “Vault unavailable on this phone”, with what it found and a note that Home and Guard still work. If the problem is a debugger, the message says so: disconnect it and open the vault again. On a phone that fails the security check before any vault exists, a vault can’t be created there.

Can the checks be wrong?

They look for common signs, and that cuts both ways. A determined person can hide root from checks like these, so they’re a safety net, not a guarantee. And like any heuristic, they can be wrong about a particular phone. The checks run each time the vault opens, so if whatever triggered them goes away, the vault opens again.

There’s no setting to skip the check. Letting the vault open anyway would mean opening it exactly where its protection can be bypassed.

Why do Home and Guard still work?

Guard doesn’t hold your files or the key that opens them. It photographs wrong unlock attempts and seals each photo for the vault with the vault’s public key, which can lock a photo but can’t open one. So Guard keeps watching your lock screen on a rooted phone, and its photos stay sealed on the phone until the vault opens there again. See how Phone Guard catches a wrong unlock.

What can you do if your phone is rooted?

  • Use the vault on a phone that isn’t rooted. If you have a backup, you can restore it on another phone.
  • Undo the root, if you rooted the phone yourself and no longer need it. Once the checks pass, the vault opens again.
  • Keep using Guard. It works on a rooted phone, and its photos stay sealed.

Is the rest of the app safe on a rooted phone?

The vault is the part that holds your files and the key, so it’s the part that refuses. Guard is less exposed: once a vault exists, each photo is sealed for it the moment it’s taken, and a sealed photo can’t be opened without the vault’s key. Without a vault, Guard keeps its photos in the app’s private storage, which root can read, so on a rooted phone treat those as visible to anything with root. Either way, the app has no internet permission, so nothing is sent anywhere from any phone, rooted or not.