A fresh ML-KEM-768 + X25519 keypair is generated and the content is encrypted to its public key. You'll receive a Recovery Key (the private key) below — store it somewhere safe and separate from this file. Anyone holding the encrypted secret cannot read it without that Recovery Key, and the hybrid stays secure even against a future quantum computer.
Add GPG LayerEncrypt with GPG before the outer layer (two-layer encryption)
GPG Configuration
Recovery Key — store separately & safely
This is the only way to decrypt the secret. It is NOT stored in this file. Keep it somewhere separate (password manager, hardware token, second device). If you lose it, the data is unrecoverable; if someone copies it together with the secret, they can decrypt.