Accessbox · Family Sharing
Set up in person, on purpose.
You can’t add someone to your Accessbox family from across the internet. The key that decrypts your family’s passwords is handed device-to-device, in the same room — so the list of people who can read your passwords is exactly the list of people you’ve stood next to. That sounds like a limitation. It’s the security model.
How setup works
- 1
One person starts as the organizer
Whoever sets things up becomes the organizer. They start the setup and their device begins looking for family members nearby.
- 2
Everyone gathers in the same room
Each member opens Accessbox on their own device and joins. Devices find each other directly over Bluetooth and Wi-Fi, without going through the internet.
- 3
You check that the codes match
Both screens show the same 6-digit number. Read it aloud. If the two devices show the same code, the connection is genuine and the organizer approves the member. If they don’t match, stop.
Why in person?
Most password managers add family members by email invitation. That’s convenient, and it’s also the weak point: an invitation is just a message, and messages can be intercepted, forwarded, or sent to an address someone else controls. Accessbox removes that path entirely. The key that unlocks your family’s shared passwords is handed from one device to another while both are in the same room. The practical effect is a rule that’s easy to remember and hard to get wrong — you can only share passwords with people you can physically stand next to.
What is the 6-digit code?
When two devices meet, they perform a key agreement — each one keeps a private half and exchanges a public half, and both independently arrive at the same shared secret without that secret ever crossing the air. The 6-digit code is derived from that shared secret. Because each device computes the code from its own copy, two matching codes prove that both devices arrived at the same secret and nothing sat in the middle rewriting the exchange. Reading the number out loud is the part a remote attacker cannot fake.
What does iCloud actually see?
Shared cards travel through iCloud, but they travel encrypted. Each card is sealed with the family key before it leaves your device, and that key is never uploaded — it only ever moves device-to-device during setup. This is why access and readability are two different things in Accessbox: even someone who somehow obtained access to the iCloud records would hold nothing but ciphertext, because the key that opens it was never there to take.
Who decides who gets in?
The organizer approves every member individually, and sees the 6-digit code for each one before approving. Nobody joins silently. Members who join later do the same in-person step. Nothing that arrives over the internet — a link, a message, a shared iCloud record — can substitute for it, because none of those carry the key.
Which devices can do this?
Setup runs on iPhone and iPad, since it depends on devices discovering each other directly. Once you’re part of a family, shared cards sync to your Mac like any other Accessbox card — it’s only the initial key exchange that needs to happen on a phone or tablet.
What if someone leaves?
A member can leave on their own, and the organizer can stop family sharing for everyone. In both cases the family key is deleted from the device’s Keychain and the cards stop syncing — but nobody loses data: previously shared cards stay on every device as ordinary personal cards. Rejoining later means doing the in-person setup again, which is the point. If someone left on bad terms, change the shared passwords; no password manager can un-see a password a person already read.
The key never travels over the internet
Your family’s encryption key is created during the in-person exchange and stored in the Keychain on each member’s device. It is never uploaded, never emailed, and never held by Roundedapps — which also means we cannot recover it for you, and cannot hand it to anyone who asks.