> For the complete documentation index, see [llms.txt](https://docs.optivalux.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.optivalux.com/product/recovery-and-protection.md).

# Recovery & Protection

Authenticators can be lost or damaged. Services can fail. Optivalux is designed so that these failures do not change who owns a product, and to **reduce the risk that an owner becomes indefinitely dependent on one failed or restrictive path**. Some availability still depends on operated services and protocol governance; see [Recovery & Continuity](/trust/recovery-and-continuity.md).

Two mechanisms serve this:

* **Recovery** restores the ability to verify the product when its authenticator fails.
* **Protection Mode** lets the owner move the certificate to a protected state when the software or verification it depends on stops working.

**Neither ever changes who owns the product.**

## Recovery

If a product's authenticator is lost or damaged, a new authenticator can be bound to the same certificate. The old authenticator is **permanently retired**. There are two ways to do this.

### Brand-assisted recovery

The owner requests recovery, and the brand authorizes it, typically after inspecting the product in person (for example at a service centre). Fresh evidence from the **new** authenticator is required.

* Requires: the owner's request, the brand's authorization, and fresh evidence from the new authenticator.
* The brand must be operating normally.
* No fixed duration is defined by the protocol; the brand's own process determines how long review takes.

### Recovery Authenticator recovery

For the pilot profile, every product has a separate **Recovery Authenticator**, registered before the first owner claims the product. It is physically distinct from the primary authenticator, can only ever be used for that one product, and cannot be added or replaced after ownership, by anyone.

* Requires: the owner's request and fresh evidence from the product's Recovery Authenticator.
* Does **not** require the brand, Optivalux or a verification service.
* Has a **14-day maturation period** during which the request can be challenged. The owner can cancel it. If the primary authenticator is still working, a fresh check of it can stop the request. This protects owners whose account access has been misused.

Recovery Authenticator recovery is the path that keeps working even if the brand is unavailable.

### What recovery never does

* **Recovery never changes ownership.** The owner before and after is the same.
* **A suspended certificate stays suspended.** Recovery can complete while a certificate is suspended, but it does not lift the suspension or restart any notice period.
* **Recovery cannot bind an arbitrary tag.** Brand-assisted recovery needs the brand's authorization; Recovery Authenticator recovery can only bind the one Recovery Authenticator registered for that product.
* **Voided certificates cannot be recovered.** Voided is terminal.
* **Recovery is blocked while the owner has reported the product lost or stolen.**

## Protection Mode

Protection Mode is for a different failure: when the software or verification that a certificate depends on stops working, or when an owner wants to move the certificate out of reach of software they no longer trust.

* The **owner** starts Protection Mode.
* After a **minimum 14-day protection period**, the certificate can move to its **protected, non-operational state**.
* The owner can **cancel** while the process is pending.
* While pending, a fresh, trusted check of the product's current authenticator can stop the process. This protects against someone who has misused the owner's account but does not have the product.
* **Ownership does not change. Certificate standing does not change.** A suspension is preserved.
* Voided certificates cannot enter Protection Mode.

In the protected state, the certificate is safe but not operational: it cannot be transferred. The brand can still suspend or void it under the normal safeguards. The owner can later move it back into normal operation, with their authorization and fresh evidence from the product, once suitable software is available.

Protection Mode does not need anyone's approval: not the brand's, not Optivalux's.

## Summary

|                        | Brand-assisted recovery       | Recovery Authenticator recovery                                 | Protection Mode                                                 |
| ---------------------- | ----------------------------- | --------------------------------------------------------------- | --------------------------------------------------------------- |
| **Problem solved**     | Authenticator lost or damaged | Authenticator lost or damaged, even if the brand is unavailable | Software or verification a certificate depends on stops working |
| **Who starts it**      | Owner                         | Owner                                                           | Owner                                                           |
| **Who else is needed** | Brand                         | Nobody                                                          | Nobody                                                          |
| **Time period**        | Not defined by the protocol   | 14-day maturation period                                        | Minimum 14-day protection period                                |
| **Changes ownership?** | No                            | No                                                              | No                                                              |
| **Changes standing?**  | No                            | No                                                              | No                                                              |

> **Current stage:** recovery and Protection Mode are implemented in the Production V2 protocol and shown in the simulated product preview. They are not yet available in connected applications. See [Current Stage](/getting-started/current-stage.md).

For the trust reasoning behind these mechanisms, see [Recovery & Continuity](/trust/recovery-and-continuity.md).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.optivalux.com/product/recovery-and-protection.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
