A backup that runs in the background is a backup that fails in the background.

The disk fills up. A folder loses permission overnight. A file is open, so it is skipped. The cable comes out at three in the morning. And the program keeps saying "all good" until the day you need it. The rival of this product is not the other backup program — it is silent incompleteness.

Elegant Vault · verified backup mirror · Windows 10 and 11

Nothing leaves your PC Nothing is deleted, nothing is overwritten Restoring and verifying never expire
Elegant Vault desk: a vault card showing the drive it is plugged into, 40,381 files and 222.3 GB, each protected folder with its file count, its size, the date of the last copy and the date of the last check, and an amber line saying 312 files unchecked for more than 90 days Elegant Vault desk: a vault card showing the drive it is plugged into, 40,381 files and 222.3 GB, each protected folder with its file count, its size, the date of the last copy and the date of the last check, and an amber line saying 312 files unchecked for more than 90 days
The desk. One card per vault, with what it actually holds: files, gigabytes, the date of the last copy and the date of the last check — per folder, not per vault. When a folder has gone too long without being checked, the card says so in words instead of staying quiet.

What it does, said once, plainly.

You pick folders and a drive you own. It copies everything 1:1 to that drive, verifies every byte with SHA-256 and shows you a seal with the counts. And your files come back through File Explorer on any PC — without this program.

Step 1 · choose

Your folders, your drive

Tick Documents, Photos, whatever you want protected — and point at an ordinary external drive. No cloud, no account, no odd formats.

Step 2 · copy & verify

A 1:1 copy, checked byte by byte

Every file is copied under the same name and the same path, and gets a SHA-256 fingerprint on the way. At the source, it only reads — it never writes.

Step 3 · see the proof

The seal — and the way-back rehearsal

At the end, five numbers on one line say what went in and what stayed out. And one button brings 20 files back and checks them, in about 40 seconds.

No jargon so far. The rest of this page is the same thing in slow motion: how the copy becomes proof.

0
files sent to a cloud — and no way for the app to reach the internet
5
counts in the seal, always printed on the same line
40
seconds: the rehearsal that brings files back and checks them
15
days of trial, no card

Nobody finds out their backup was incomplete on a good day.

The category's number one failure is not a program that crashes. It is a program that finishes, reports success, and left things behind.

  • The file that was open. A spreadsheet you had not closed, skipped without a word, on every run for a year.
  • The folder that lost permission. One inherited ACL changed, and a whole branch stopped being copied.
  • The photo that lives only in the cloud. Zero bytes on disk, a full-size entry in the listing, and nothing behind it.
  • The name the destination cannot take. A colon in a file name, a path past the limit, a 6 GB video on a FAT32 stick.
What a silent backup reports Backup completed successfully. What Elegant Vault reports 1,204 copied · 1,204 of 1,204 checked · 0 mismatches · 25 refused on purpose · 12 failed

The five counts are one string in the source, not five labels a screen can pick from. "Zero mismatches" next to twenty-five refusals and twelve failures is not a result — it is a sentence with the ending cut off, and a test forbids cutting it.

Part of the Elegant family, and not a dependency of it.

Elegant File Explorer organizes files by rules; Elegant Vault keeps a verified copy of them on a drive of your own. Neither app requires the other, and nothing on this page needs the sibling installed.

Meet Elegant File Explorer

Proof, not a promise.

"Copied" is a word a program writes about itself. This one swaps the word for a sum you can redo on your own, with a tool that already came with your Windows, on a computer where this app is not even installed.

Five pieces. None of them is an invention of ours: they are old durable-write practice, assembled in the order that makes silence impossible.

The vault is an ordinary folder. the same relative paths as the source No container, no database in the middle if this program vanished tomorrow, the files would still be there
01

The staircase: temporary name, real disk, final name.

Every file is born with a temporary extension, has its bytes pushed to the medium — not to the cache, which is gone the moment the power is — and only then earns its definitive name, in a swap Windows does not leave half done.

A correct name inside the vault exists only if the file got there whole.

This is not an optimistic copy with a check bolted on afterwards. The order is the product.

02

SHA-256 a7f3…9c1b · in the same pass as the write

The fingerprint leaves with the copy, not after it.

The bytes go past once: on their way to the vault the SHA-256 sum is computed over them, and each file becomes one line of the manifest.

There is no second reading to "generate the hash later" — so there is no window in which the file changed between the two passes and nobody noticed.

03

The manifest never promises a file that did not arrive.

The vault's list is a text file that only grows, written in batches that are pushed to the disk.

The guarantee has a name and is tested as a mathematical property: the durable manifest is always a prefix of reality. Pull the cable whenever you like — the worst case is a manifest that knows less than the disk. Never more.

That is why unplugging mid-copy is a pause and not an error. Plug the drive back in and the copy carries on from where it stopped.

04
certutil certutil -hashfile "<file>" SHA256 compare it with the manifest line

Checking is re-reading the bytes — and you can do it without us.

The app's own check re-reads the vault and compares it against the manifest, file by file, and says how long it will take before it starts. But the proof is not held hostage by the app: the LEIA-ME.txt written at the root of the drive teaches you, in three languages, how to check one file by hand with the certutil that already ships with Windows.

Where a path is too long for File Explorer and for certutil, the interface says so: Vault copies and restores those files, but for them the check by hand does not work.

05
vault.json · at the root of the drive LEIA-ME.txt · trilingual, four points nothing here needs Vault

The drive says it is the vault. Our settings do not.

The identity is written at the root of the destination, so a new drive letter, another dock, another PC or a reinstalled Windows changes nothing: the vault is still the vault, and the local index can be rebuilt from the destination. The program is the convenience; the drive is the backup.

None of these five pieces appears as an option you can switch on. They are the only path a write takes here — the engine has no fast mode that skips the fingerprint, because the fast mode is exactly where the silence would get in.

1:1
the same relative paths as the source, no proprietary format
SHA-256
for every file, in the same pass as the write
0
of your bytes on the internet — the program has no network capability
20
drawn files come back from the vault in the rehearsal — each checked byte by byte, in front of you

None of this depends on your attention or on a setting: it is the only way the program knows how to write. And when something cannot be verified, the Vault says so — it never pretends.

The numbers come first. Then the first byte.

Every copy starts as a simulation — a plan with no writing in it at all. How many files go in, how many bytes, how long, how much room is left afterwards. And, with the same prominence, what is not going in, split into two buckets from the start: a refusal and a failure are not the same news.

Elegant Vault simulation: 1,204 files will go in and 4.7 GB, 39,177 are already identical in the vault, an estimated time of 6 min 12 s, an amber notice that it fits but barely, and the section What stays out and why with two side-by-side lists — refused on purpose with 25 items and failed with 12 Elegant Vault simulation: 1,204 files will go in and 4.7 GB, 39,177 are already identical in the vault, an estimated time of 6 min 12 s, an amber notice that it fits but barely, and the section What stays out and why with two side-by-side lists — refused on purpose with 25 items and failed with 12
The simulation. Nothing has been written yet. The two lists sit side by side, each item with its reason, its count and the bytes it represents — and the first few paths spelled out, so "25 refused" is never an abstraction you have to trust.
01

It is cloud-only

A placeholder that would have to be downloaded before it could be copied. Vault reads the reparse tag rather than the file, so asking about it never triggers a download you did not ask for.

refused on purpose
02

It is a live database or cache

A file being written to right now would arrive inconsistent, and an inconsistent copy of a database is worse than no copy, because it looks like one.

refused on purpose
03

The destination cannot hold it

A name the destination file system will not accept, a path beyond the limit, or a file over 4 GiB on FAT32. Refused with the reason, never truncated into something that only looks right.

refused on purpose
04

Another program had it open

Vault runs as you, with your token, and does not use Shadow Copy — that would need an administrator. A locked file becomes a named line instead of a silent gap.

failed
05

Windows denied access

The folder whose permissions changed and nobody noticed. It is counted, weighed and named, and it is the reason a plan that says "12 failed" is more useful than one that says nothing.

failed
06

The read itself went wrong

A bad sector, a cable that dropped, a drive that stalled. "I could not look" is never recorded as "I looked and found nothing" — those are three different states in the engine, never two.

failed

Both lists can be saved as CSV, next to the list of what actually went in — ordinary files you can keep, mail to yourself or open in a spreadsheet without this program. Speed is not on this page for a reason: it depends on your drive, your cable and your enclosure. The app estimates it on screen, on your machine, before it acts — and a screen estimate does not become a shop-window number.

One line, five numbers, no way to print half of it.

At the end of a run, the vault's manifest is sealed and the result is written once — copied, checked, mismatches, refused on purpose, failed. The same line is repeated in the status bar. If that seal could ever appear broken in half, it would be a maximum-severity bug in this product, not a cosmetic one.

Elegant Vault run seal: the line 1,204 copied, 1,204 of 1,204 checked, 0 mismatches, 25 refused on purpose, 12 failed, a notice about three files with paths too long for File Explorer, three buttons that save CSV reports, and a card offering to check what this run copied or the whole vault with the estimated time said first Elegant Vault run seal: the line 1,204 copied, 1,204 of 1,204 checked, 0 mismatches, 25 refused on purpose, 12 failed, a notice about three files with paths too long for File Explorer, three buttons that save CSV reports, and a card offering to check what this run copied or the whole vault with the estimated time said first
The seal, and the check that follows it. Verifying re-reads the bytes in the vault and compares them against the manifest. "Check the whole vault" is the gesture that finds media that decayed in silence, and the time it will take is said before you press it, not after.
E:\ElegantVault\_vault\manifest.jsonl relative path · size in bytes · modification time · SHA-256 append-only text, one line per file, with the layout version in the envelope the manifest is always a prefix of reality · it never lists a file that did not arrive whole

Because the fingerprint was computed in the same pass as the write, verifying afterwards compares two independent readings of your file rather than the same one twice. The manifest is text. You can open it in Notepad.

Most backups are never tested. This one tests itself in 40 seconds.

The rehearsal draws twenty files out of the vault, brings them back into a temporary folder, checks each one's SHA-256 against the manifest, shows you the result — and then deletes only what it created itself. Nothing of yours is touched, and the folder is gone at the end.

It is the whole product demonstrated at once: the copy arrived, the fingerprints match, and the files come back. The draw is stratified — the largest files, the ones longest without a check, the longest paths, and an even sample of the rest — so it cannot be gamed by leaving twenty easy files in a corner.

Draw twenty, across four strata Bring back into a temporary folder Check SHA-256 against the manifest Report two verdicts, never merged Delete only the folder it created
Elegant Vault rehearsal: the heading Bringing 14 of 20 — checking each one's SHA-256 against the manifest, then a numbered list of files with a green tick, the reason each one was drawn (among the largest, longest without a check, among the longest paths, drawn evenly) and its size, with one line marked beyond File Explorer's reach Elegant Vault rehearsal: the heading Bringing 14 of 20 — checking each one's SHA-256 against the manifest, then a numbered list of files with a green tick, the reason each one was drawn (among the largest, longest without a check, among the longest paths, drawn evenly) and its size, with one line marked beyond File Explorer's reach
The rehearsal, running. One line per file, with why it was drawn written next to it. The two verdicts are kept apart on purpose — "Vault brought back twenty of twenty" and "three of them did not match" are different facts, and merging them is how a backup tool ends up lying with true numbers.

A rehearsal is not a restore, and the app never pretends otherwise: it is a sample, drawn without replacement, reported honestly. The real restore is its own screen, with its own simulation — file, folder or the whole vault — and it never overwrites anything: what comes back arrives beside what is already there, with a suffix, or in a new folder. Restoring and verifying never expire, not even after the trial.

If this program disappeared tomorrow, your files would still be there.

The vault is not an archive, a container or a database. It is your folder tree, with the same relative paths, written as ordinary files — the format every PC on earth already reads.

  • Open it in File Explorer and drag things back. No import, no account, no version of this app that has to still exist.
  • Check a fingerprint by hand. A trilingual LEIA-ME.txt at the root of the drive gives you the exact command, using the certutil that already ships with Windows.
  • The vault's identity lives on the drive, not in our settings. A new drive letter, another dock, another PC, Windows reinstalled: the vault is still the vault.
  • Nothing is compressed, deduplicated or encrypted. That is a decision, not an omission — encryption would trade a readable copy for a box only our program can open.
E:\ElegantVault\ LEIA-ME.txt · how to drag back, how the paths mirror the source, how to check by hand, and "nothing here needs Vault" vault.json · the drive identifies itself _vault\ · manifest, reports and the app's own bookkeeping Documentos\Contratos\2026\aditivo-fornecedor.pdf Imagens\2026\05\casamento-raw\DSC_9931.NEF

The names _versions\ and _vault\ are reserved at the root of the destination from day one, so the features planned for 1.x arrive without a migration. Not a line of 1.0 uses the first one — it is a reservation, not a feature.

Nothing is deleted. Nothing is overwritten.

Not in the source, not in the vault, not during a restore. Not as a hidden option, not as a checkbox, not as a setting we chose to default off.

It is structural, and it is the decision the whole product is built around. The worst bug a backup program can have is the one that destroys the backup — so version 1.0 simply does not contain the code that could. Deleting, moving and replacing are banned calls in the sources, swept by an architecture test on every build.

The handful of commented exceptions all touch artefacts the app made itself: its own temporary file, its own rehearsal folder, its own catalogue. Not one of them has a byte of yours inside.

  1. 1
    At the source, it only reads.

    There is no verb in this app that deletes, moves or renames a file of yours. The read side is read-only by construction, not by policy.

  2. 2
    A plan you saw, before anything is written.

    The simulation is a pure function with no writing in it, and the copy is a second gesture. Two gestures, always — there is no one-click that skips the numbers.

  3. 3
    Every file is written on a ladder.

    A temporary name, then a flush that pushes the bytes to the actual disk rather than the cache, and only then the final name. A yanked cable leaves no half-file wearing a real name.

  4. 4
    The manifest never runs ahead of reality.

    What the manifest promises has already arrived. That is what makes the vault trustworthy after a crash, and it is checked in the build as a property, not as an anecdote.

  5. 5
    A leftover file becomes a report line.

    You deleted something at the source? The copy in the vault stays, and shows up in a report with its size. Deciding what to do with it is yours; version 1.0 has no code that could do it for you.

  6. 6
    Restoring never overwrites.

    What comes back arrives beside what is already there, with a suffix, or in a new folder. A restore that silently replaces the good file with an old one is the second-worst bug in this category, and it is unbuildable here too.

The cost of never deleting, said out loud. A vault that never removes anything grows for as long as you use it. Files you deleted at the source stay in the vault as report lines with their size added up, and renaming a large folder at the source produces two trees in the vault rather than one, because 1.0 has no code that matches a move. Pruning, with the guards it deserves, is 1.1 — and it arrives together with the matcher, or not at all.

Complete on its own. With its sibling installed, it counts what it can add.

Integration is a bonus and never a toll. What is not genuinely available on your machine does not appear at all: no dead buttons, no notice explaining what you are missing.

Show it in Explorer.

At the end of a copy, a check or a restore, the folder opens with the file already selected — inside Elegant File Explorer, if you have it.

The siblings' folders arrive pre-ticked.

If Elegant Paper or Elegant Photo Cleaner is installed, the folders where they keep your work are suggested as sources when you create the vault — ticked, and easy to untick.

A shield in the Explorer toolbar does not exist.

Vault publishes what it covers for the family to read, but the other side has no verb for it yet. When it does, it gets counted like the rest — and not one day before.

Meet Elegant File Explorer

One price, once.

US$ 12.99US$ 24.99launch priceone-time purchase — yours forever
  • 15-day trial on your PC, no card and no account.
  • Restoring and verifying never expire. When the trial ends, the gate blocks only the verb that copies. Your files keep coming back, forever.
  • One-time purchase. No subscription, no renewal and no feature that disappears when a monthly fee lapses.
  • 1.x is a free update, promised in writing — versions, pruning and network destinations land there.
  • Nothing leaves your PC. No file, no file name, no fingerprint.
  • Three languages from day one, switched without restarting, and light, dark or automatic crossed with classic or modern.
  • Windows 10 version 1809 or newer, and Windows 11. 64-bit.

Elegant Vault is on the Microsoft Store. One price, paid once — no subscription and no renewal.

Known limits.

Saying it costs less than hiding it — and in a backup product, hiding it costs somebody's files. All of these are consequences of decisions we would make again.

  • Version 1.0 keeps no older versions of a file. The vault mirrors the source as it is now: it protects you against a drive that dies, not against saving over a good file yourself. Versions arrive in 1.1, a free update — and the format already written to the drive reserves their layout, so nothing will have to be migrated. Keeping versions needs pruning code, and pruning is this category's largest "deleted what it should not have" surface.
  • There is no schedule and no automatic copy. No background service, no startup task, no command line that copies on its own. With the app open, plugging the vault drive in opens the simulation; copying waits for your click. The market's number one complaint is the run that failed in silence, and this is the decision that lets the product promise the opposite. Scheduling is 1.2.
  • The destination is a local mounted drive, not a NAS. A sleeping network share can block inside Windows itself for the best part of a minute, and shipping that without the engineering it needs would be a freeze you would rightly blame on us. Network destinations are 1.1–1.2 work.
  • A file another program is holding open stays out, by name. There is no volume snapshot, because it would need administrator rights — something no app of this house asks for. The upside is real: this product cannot be taken down by the Windows updates that broke third-party backups through VSS timeouts. The downside is real too, and it appears with its path in the "failed" list instead of vanishing into an error counter.
  • Files that exist only in the cloud stay out until you ask for them. Copying one means downloading it whole, so the decision is yours and is taken folder by folder, with the bytes said first. Until then it sits in the "refused on purpose" bucket with the reason written next to it — and Vault reads the placeholder's tag, never the file, so asking about it never triggers a download.
  • A very long path is copied, but cannot be checked by hand. Vault copies and restores those files normally. It is File Explorer and certutil that cannot reach those paths — and the app says how many files are in that state instead of letting you find out the day you need them.
  • Verifying proves the copy, not the read. If the source was already handing over corrupted bytes, the vault faithfully receives and verifies a corrupted copy. No checksum on earth fixes that.
  • Detecting decay is not repairing it. Checking the whole vault tells you which files diverged and leaves the decision to you. There is no parity data and no self-healing in 1.0.
  • A vault that never deletes grows forever. Files you removed at the source stay in the vault as report lines with their size added up, never as an automatic deletion — and renaming a 40 GB folder at the source creates a second 40 GB tree instead of moving the first. Pruning with guards and move matching arrive together in 1.1, or not at all.
  • One copy is not a backup strategy. A vault kept in the same room as the computer does not protect against fire, theft or a lightning strike. Keep more than one copy, in more than one place — Vault helps with one of them, not with all.
  • The vault is not encrypted. Anyone holding the drive can read it, which is the very property that makes the copy readable on any PC without this program. Compression and encryption were left out for that reason. If the drive travels, encrypt the volume with the tool your edition of Windows provides.
  • The package is 64-bit. On an ARM machine it runs under emulation. There is no macOS or Linux version.

Frequently asked questions.

Do my files leave my computer?

No. The app has no way to connect to the internet — the vault is a drive you plugged in yourself. The only connection that exists is the licence and 15-day trial check against the Microsoft Store, made by Windows' own API, and it is fail-open: if the Store cannot be reached, the access you already had stays.

Can Elegant Vault delete or overwrite something of mine?

No, and that is the rule the product is built around. Version 1.0 is purely additive: at the source it only reads, and there is no verb in the app that deletes, moves or renames a file of yours, not even as a hidden option. The few deletion calls that exist in the sources touch the app's own temporary files, its own rehearsal folder and its own catalogue — and the program has no ability to grow a sixth: the rule is part of how it is built, not a setting. A file left over in the vault becomes a line in a report, never a deletion.

Can I get my files back without this program?

Yes, and that is the point. The vault is an ordinary folder tree with the same relative paths as the source. Any PC with File Explorer opens it and drags files back. There is no container, no database and no proprietary format in the middle. A trilingual LEIA-ME.txt written at the root of the drive explains how to drag files back and how to check a fingerprint by hand with certutil, which already ships with Windows.

What happens if I unplug the drive in the middle of a copy?

That is a pause, not an error. Every file is born under a temporary name, is pushed to the actual disk rather than to the cache, and only then gets its final name. The manifest is always a prefix of reality: it never lists a file that did not arrive whole. Plug the drive back in and the copy resumes where it stopped.

Does it keep older versions of my files?

Not in 1.0, and we would rather say it than let you find out. Version 1.0 protects you against a drive that dies, not against saving over a good file yourself. File versions are planned for 1.1, which is a free update for anyone who bought 1.0. The format written to the drive already reserves the layout for them, so the update will not need a migration.

Does it run on a schedule, or copy on its own?

No. There is no scheduler, no background service and no startup task. The market's number one complaint about backup is the run that failed in silence, so this product sells the opposite: a backup you watch happen. Plugging the vault drive in with the app open opens the simulation; the copy itself waits for your click. Scheduling is planned for 1.2.

What happens when the 15-day trial ends?

Restoring and verifying never expire. When the trial ends without a purchase, the gate blocks only the verb that copies: bringing your files back, checking the vault and rehearsing a restore keep working, forever. A backup that holds hostage the files of someone who did not pay is indefensible.

Do I need Elegant File Explorer?

No. Elegant Vault is complete on its own. If the sibling is installed, the app can open the folder you just restored with the file already selected. Whatever is not genuinely available on your machine does not appear at all: no dead buttons and no notice explaining what you are missing.

The backup you never tested is the one you are relying on.

Elegant Vault copies your folders to a drive of your own, proves file by file that the copy arrived whole, and lets you watch it happen — then brings twenty of them back in forty seconds to show you it works.

On the Microsoft Store. Windows 10 version 1809 or newer, and Windows 11.