Backup the vault
Vault and settings — Backup the vault
Where: Key store → Backup vault. The live file path is shown there and under Settings → Key store.
The vault file (.ngw3) is the database: keys, logins, groups, settings, audit. Exporting one public key is not a vault backup.
Find the file
- Settings → Key store, or the “Current vault” box on Backup vault.
- Read the path (default %AppData%\NEXTGEN Widget Encrypt3\vault.ngw3).
- That is the file you must copy.
Make a backup (manual)
- Key store → Backup vault → Copy vault backup. Choose where to save the .ngw3.
- Or exit or lock Encrypt3, then copy the .ngw3 in Explorer.
- Store the copy offline (other disk or USB, not only the same PC).
- The copy is still encrypted. You need the vault login from the day you made the copy.
Back up after you compose, import, revoke, or add an administrator.
Scheduled (automatic) backup
Same page: Scheduled backup. Off until you turn it on.
- Check Create automatic backups while signed in.
- Browse to a folder that is not only the AppData vault folder.
- Choose Daily, Weekly (weekday list appears), or Monthly (day 1–28 appears).
- Set the time (24-hour).
- Keep last N files. Names look like vault-20260920-1800.ngw3. Older copies in that folder are removed.
- Click Save schedule.
The copy runs only while Encrypt3 is signed in. If the day and time pass while the program is closed or locked, that slot is skipped until you sign in after that time; then one copy is made. Failures go to the audit log. This is still a file copy of the encrypted vault — it does not store the login password next to the backup.
Restore test
On Backup vault, Restore test only checks that the file has a valid vault header. It does not replace the live vault.
Restore
- Close Encrypt3.
- Replace the current vault file with the backup, or in Settings → Key store point the path at the backup .ngw3.
- Start Encrypt3 and sign in with the username and password that were in force when that backup was made.
- Confirm Settings → Key store still points at the file you meant.
- Open the grid and check key count and a known fingerprint.
Test restore before a disaster, using a spare copy, not your only backup.
Move vs backup
Change location copies the live vault to a new path and remembers it. That is not a dated backup. Keep a separate dated copy anyway. Scheduled backups are dated copies; moving the vault is not.
If it fails
- Restored an old .ngw2 or a key .asc by mistake — those are not this vault format.
- Wrong password on a good backup — that is the vault login from the day you made the copy.
- Copied the exe but not the .ngw3 — the program on another PC starts empty or points at a different path.
- Expected Friday’s automatic copy but the program was not signed in at that time — sign in and wait for the next check, or use Copy vault backup once.
Next
Move the vault if you only want a new working path. Two passwords if you are unsure which password opens a backup.