Enable Vault mode

Keep all library files stored on your device only — files never leave your machine.

Vault mode is a workspace-level setting in the Contextium desktop app. When it's on, all new files you create in the workspace are written to an encrypted local database on your device and never uploaded to Contextium's servers. Your team's agents, skills, and workflows continue to sync from the cloud so your AI context stays consistent.

Vault mode requires a Team plan or above.

Turn Vault on

  1. Open the Contextium desktop app.
  2. Go to Settings → Vault.
  3. Toggle Vault on — the toggle turns amber when active.

What changes when Vault is on

  • New files go to your local encrypted database — not Contextium servers.
  • Existing cloud files are unaffected and stay accessible when you're online.
  • Agents, skills, and workflows still sync from the cloud.
  • External sync (Google Drive, OneDrive) is disabled for libraries in Vault mode.

Turn Vault off

Toggle Vault off in Settings → Vault.

Files written while Vault was on stay on your device — they are not automatically uploaded when you turn Vault off. To move them, use the CLI:

contextium files list
contextium files create

Private audit log

The desktop app keeps a local audit log of all actions on Vault and private libraries. To view it:

  1. Go to Activity in the desktop app.
  2. Select the Private tab.

The Private tab is only visible to workspace owners and admins. Each entry shows the timestamp, action (create, update, delete, view), file name, and library.

To save a copy, click Export CSV.

Vault mode vs per-library Vault storage

Vault mode (Settings)Library Vault (Library Settings → Storage)
ScopeEntire workspaceOne library
PlanTeamPro
Who sets itAny member (on their device)Library owner
Audit logYesYes (same log)