If you're unreachable, can your company operate?

Somewhere in every startup there's a credential only the founder holds: the domain registrar, the root AWS account, the bank token, the recovery key to the company password manager. That's a bus factor of one — and it doesn't take a tragedy to trigger it. A hospital stay or a lost phone in another country can freeze payroll, deploys, and DNS.

The access map nobody drew

Teams document architecture and processes, but almost nobody documents access — because writing down where the keys live feels like a security hole. So the map stays in the founder's head. Investors call this key-person risk; engineers call it a bus factor; either way, it's the single cheapest existential risk to fix.

Why the usual fixes fall short

The dead-man-switch approach

A dead man's switch keeps the emergency map sealed while you're reachable and delivers it only when you're provably not. With Capsulene, you seal a continuity capsule — encrypted in your browser before upload, so its contents exist nowhere in readable form — and answer a periodic check-in email. Go permanently silent, and after the grace period and reminder ladder it releases to the person you chose. Update it whenever access changes; pause or delete it any time.

What goes in a continuity capsule

  1. The first 48 hours. Who takes charge, who to inform (counsel, board, key customers), what to freeze.
  2. Root access. Registrar, DNS, cloud root accounts, password-manager recovery kit.
  3. Money. Banking access procedure, payroll timing, who signs.
  4. Locations, not just secrets. Where contracts, cap table, and insurance policies live.

Seal a business continuity capsule — free to start, encrypted before it leaves your browser.

Create a continuity capsule

Frequently asked questions

What credentials should a founder continuity capsule contain?

The access nobody else has: domain registrar, DNS, root cloud accounts, code-signing keys, banking tokens, the password-manager recovery kit, and a short 'first 48 hours' instruction list naming who does what.

Who should the recipient be?

A co-founder, your operations lead, company counsel, or a board member — someone with the standing to act. The capsule releases to them only after your check-ins go unanswered through every grace period and reminder.

Is this a substitute for proper access management?

No — shared vaults and role-based access should come first. The capsule covers what those can't: the recovery keys and top-level credentials that, for good security reasons, only you hold.

Related: crypto inheritance · family emergency access · how capsules work