Finocket keeps a copy of your books on your device so the app works with no signal. That copy is encrypted, and today the only things that open it are the passcode set on that device and that person’s own recovery key. Finocket holds neither.
Organisation key escrow is the name for changing that on purpose: adding a second key, held outside the device, so somebody other than the person who set the passcode can open a device’s local data. It is off for every organisation, and this guide explains what it would mean, because it is the kind of thing you should understand before you are asked, not after.
Where your organisation stands right now
Escrow is off. No organisation on Finocket has it on. Nothing you do on the Settings → Account & privacy → Organisation key escrow screen changes that today — the screen exists so the choice is visible and explained rather than arriving one day as a switch nobody understands.
If you forget your own passcode, escrow is not the answer and never was. Make a recovery key. That is a second way in that stays entirely in your hands.
What escrow would change
- An administrator could open a device’s local books without that person’s passcode.
- It would apply to everyone in the organisation, including people who did not set it up and who set their passcode believing nobody else could open their data.
- It would apply to books already on devices, from the moment each device next unlocks — not only to work done afterwards.
- Finocket would be able to decrypt that organisation’s books. That is not true today, and it is the sentence an owner would have to tick before anything was switched on.
Why it exists as an idea at all
Because staff leave. A firm genuinely owns its clients’ books, and a bookkeeper who resigns without handing over a passcode can leave work stranded on a laptop that nobody can open. Large organisations solve this the same way — a recovery key held centrally rather than by the person using the machine.
It is a real trade, not a trick: an organisation gains the ability to get into its own data and gives up the guarantee that only the person at the keyboard can. Which side of that trade is right depends on the organisation, which is why it is a choice made per organisation and never a default.
Turning it off again does less than it sounds
This is the part worth reading twice. Turning escrow off stops new keys being made. It cannot withdraw a key that has already been made and copied — a copy that has been taken cannot be un-taken by deleting the original.
The key that encrypts your books does not change when escrow is switched off, so somebody holding an older escrow key could still open data written afterwards. Genuinely withdrawing access to books that were already escrowed would mean re-encrypting every workspace from scratch, which is a different and much larger operation than flicking a switch.
The practical consequence: escrow is best thought of as a window. Between the day it went on and the day it came off, somebody other than you could open your local books. Finocket records both dates so that window is a known fact rather than a guess.
How you would know
If your organisation ever turns escrow on, the setting is visible to every member of the organisation — not only to the owner who set it. Open the Organisation key escrow screen at any time and it will tell you the state and the date it changed.
What has not been decided
Deliberately, and stated here rather than left vague: Finocket has not settled who would hold an escrow key or where it would be kept. Until that is decided and published, escrow cannot be switched on by anybody — the screen says so and the button does nothing. We would rather show you an honest “not yet” than a control whose consequences we cannot describe exactly.
