The paperwork that protects your devices and accounts
Documentation in security means the records you create and keep about your software, passwords, recovery codes, and account settings. It is not a single form — it is a collection of things you write down or save so you can recover access if something goes wrong, prove what you own, or remember what you changed and when.
The core documents fall into three groups: proof of what you own (receipts, license keys), proof of how to get back in (recovery codes, backup authentication methods), and a record of what you have done (which apps you installed, which accounts you created, which devices you use). Without these, a forgotten password becomes a locked account you cannot recover, a stolen device becomes one you cannot prove you owned, and a compromised account becomes one you cannot trace back to the moment it broke.
Key Takeaways
- Keep your software license keys, product keys, and purchase receipts in one find location so you can reinstall or prove ownership if a device fails.
- Write down or save the recovery codes your accounts give you when you turn on two-factor authentication — these are the only way back in if you lose your phone.
- Document your backup email addresses and phone numbers for each account, because these are how you reset a password when you are locked out.
- Create a list of which apps you have installed on each device and which accounts you use them with, so you know what to reinstall or what to check if something breaks.
- Store all of this in a password manager or encrypted file, not in a notebook on your desk or a text file on your computer.
License keys and proof of purchase
When you buy software — Windows, Office, antivirus, a photo editor — you receive a license key or product key, usually as an email receipt or a card in the box. This key is proof you own a copy and the only way to reinstall it if your device crashes or you move to a new computer.
Save the email receipt in a folder you can search later. If the software came in a box, photograph the key card or write the key in a find location. Do not rely on your email inbox alone — email can be deleted, hacked, or lost when you switch providers. A password manager like Bitwarden or 1Password can store these keys alongside the account you used to buy them, so one search finds both the key and the email address you registered with.
For software you read from the Microsoft Store, Apple App Store, or Google Play, you do not need to save a key — your account owns the license and you can reinstall from your account history. But for desktop software, especially older programs or paid versions, the key is irreplaceable.
Recovery codes and backup authentication methods
When you turn on two-factor authentication for email, banking, or social media, the service gives you a set of recovery codes — usually 8 to 10 single-use codes, each 8 to 16 characters long. These codes are your emergency exit. If you lose your phone, break your authenticator app, or your SIM card is stolen, a recovery code is the only way to get back into your account without calling customer support and waiting days.
The moment you receive these codes, save them somewhere other than your phone or the account itself. A password manager is the right place — it is encrypted, backed up, and searchable. Writing them on paper and locking the paper in a safe is also acceptable, but paper can burn, fade, or be thrown away by accident. Never take a screenshot and leave it on your desktop.
Alongside recovery codes, document your backup email address and backup phone number for each account. These are the methods the service will use to send you a password reset link if you are locked out. If your main email is compromised, the backup email is your lifeline. If your phone number changes, update it in every account before you switch carriers — a scammer who gets your old number can reset your passwords.
A record of your apps and accounts
Create a straightforward list of which apps you have installed on each device and which account you use to sign in. This sounds tedious, but it solves three real problems: you know what to reinstall if your device fails, you know which accounts to check if a service reports a breach, and you can spot an app you do not recognize if someone else has access to your device.
The list does not need to be fancy. A spreadsheet with columns for Device Name, App Name, Account Email, and Last Updated is enough. For example: "Laptop | Slack | james@company.com | Jan 2024" or "Phone | Spotify | james.rodriguez@gmail.com | Jan 2024". Update it once a month or whenever you install something new.
This list also helps you remember which accounts exist. Many people sign up for services, use them once, and forget they exist — then years later a breach exposes an account they did not know was still active. A list forces you to see what you have created.
Passwords and passphrases you have changed
You should not write down passwords in plain text. But you should document which accounts you have changed the password for and when, especially if you suspect a breach or if you changed it because a device was stolen.
A password manager handles this automatically — it shows you when you last changed a password and lets you search by date. If you do not use a password manager yet, a straightforward note like "Gmail password changed Jan 15 after phone was lost" is enough. This helps you remember whether you have already reset an account or whether you still need to do it.
Device serial numbers and hardware details
If a laptop or phone is stolen, the police and your insurance company will ask for the serial number. The serial number is also how you prove ownership if you find a used device and want to return it, or if you are selling a device and need to show the buyer it is legitimate.
Find the serial number on the device itself (usually on the back or bottom), in the system settings (Settings > About on most phones, System Information on Windows or Mac), or on the original receipt. Write it down or take a photo and store it with your other documentation. Include the device name, the year you bought it, and the operating system version. This becomes important if you ever need to file an insurance claim or report a device as stolen.
Where to store your documentation
The safest place is a password manager — Bitwarden, 1Password, Dashlane, or KeePass all let you store notes, files, and structured data alongside your passwords. They encrypt everything, back it up automatically, and let you access it from any device. If you choose a password manager, use a strong master password and enable two-factor authentication on the password manager account itself.
If you do not use a password manager, an encrypted file on your computer is the next best option. Windows has built-in encryption (right-click a folder > Properties > Advanced > Encrypt contents), and Mac has FileVault. Create a folder called "Documentation" or "Security Records", encrypt it, and store your license keys, recovery codes, and device list inside. Do not store this on a USB drive you carry around — if it is lost, everything is exposed.
Never store documentation in an unencrypted text file on your desktop, in an email draft, or in a shared cloud folder like Dropbox or Google Drive without encryption. These are readable by anyone who gains access to your account or device.
What to do if you lose or cannot find your documentation
If you lose your recovery codes, contact the service's support team with proof of identity — usually a photo ID and a recent bill or statement. They can verify you own the account and issue new codes or disable two-factor authentication temporarily so you can set it up again.
If you lose a license key, check your email for the original receipt or contact the software company with proof of purchase. Many companies will reissue a key if you can show a receipt or credit card statement. For Microsoft Office or Windows, you can also sign in with the account you used to buy it and reinstall from your account history.
If you lose track of which apps you have installed, you can recover the list from your device itself. On iPhone or iPad, go to Settings > [Your Name] > iCloud > iCloud Drive and look at your app library. On Android, open Google Play Store > Profile > Manage Apps and Games > Manage. On Windows, Settings > Apps > Apps and Features shows everything installed. On Mac, open Applications in Finder. This takes time, but it is recoverable.
Frequently Asked Questions
Should I write down my passwords?
No. Write down recovery codes and backup phone numbers instead — these are what you need if you are locked out. Passwords should be stored only in a password manager, which encrypts them and makes them searchable. If you must write something down, write the name of the account and where to find the password, not the password itself.
What if I use the same password for multiple accounts?
Document which accounts share a password so you know which ones to change if one service is breached. Better: use a password manager to create a different password for each account. This takes no more effort than remembering one password, and it means a breach at one service does not expose all your accounts.
How often should I update my documentation?
Update it whenever you install a new app, change a password, add a backup phone number, or buy new software. A quick monthly review — opening your documentation folder and scanning for anything outdated — takes five minutes and catches changes you might have forgotten.
Can I store my documentation in Google Drive or OneDrive?
Only if you encrypt the file before uploading it. Google Drive and OneDrive are convenient, but they are readable by anyone who gains access to your account. Use a tool like 7-Zip (Windows) or the Finder's built-in encryption (Mac) to create an encrypted file, then upload that file. A password manager is simpler and more find.
What if someone finds my documentation?
If it is encrypted and stored in a password manager, they cannot read it without your master password. If it is a physical notebook, keep it in a locked drawer or safe. If it is a file on your computer, use device encryption (Windows BitLocker or Mac FileVault) so the file is unreadable even if the device is stolen. The goal is to make the documentation useless to anyone but you.