Security & privacy

Built so nobody — not even us — can read your data without your authority.

Sensitive material lives in FutureVault, a SOC 2 Type II custodian. Plaintext on our servers is limited to data you choose to display. Every access by your executor is logged with name and timestamp.

Security & privacy

Built so nobody — not even us — can read your data without your authority.

Sensitive material lives in FutureVault, a SOC 2 Type II custodian. Plaintext on our servers is limited to data you choose to display. Every access by your executor is logged with name and timestamp.

Six pillars of our security model.

01

Zero-knowledge for secrets

Private keys, recovery phrases, full account numbers, and document blobs live in FutureVault — never our database. We hold pointers, not contents.

02

Encryption everywhere

At rest: AES-256-GCM on every sensitive column. In flight: TLS 1.3. Backups are encrypted with separately-rotated keys.

03

Identity gate before any reveal

Government ID + selfie + PIN, or the affidavit fallback. Every unlock is reviewed by a human before access opens.

04

Cooling-off + dispute

A 7-day window after verification (30 days if no PIN). Other named designees are notified and can dispute. Nothing opens silently.

05

Audit log on every reveal

Every time an executor reveals a sensitive value or downloads a document, we log who, when, and what. Subpoena-able.

06

No data sale, ever

We don't sell your data. Sponsorship of the Estate Plan is opt-in: you choose if Barrett Tax Law or Donsky & Donsky sees your file.

Different data, different storage. By design.

Data typeWhere it livesWho can read it
Email, name, plan, roleOur Postgres databaseYou, authorised staff (for support)
Will Registry metadataPostgres (executor contact encrypted)You always; verified searchers per their tier
Treasure Map asset descriptionsPostgres JSONBYou always; lawyer only on items you toggle on; executor after unlock
PINs, keys, account numbersFutureVault (encrypted, SOC 2 II)You always; executor after full unlock + log
Document uploadsFutureVault encrypted blob storageReviewers during verification, then sealed
Audit logAppend-only Postgres + cold archiveYou, your executor, our compliance team
If the worst happened

Our database alone wouldn't hand over your estate.

Even with full read access to our Postgres database, an attacker would see asset descriptions and metadata — not the values that let someone actually take anything. The keys, account numbers, and recovery phrases live in FutureVault behind a separate encryption boundary and a per-user unlock path.

We follow PIPEDA (Canada) and applicable provincial privacy law. If we ever detect a real breach, we notify affected users within 72 hours and the Office of the Privacy Commissioner where required.

Practical safeguards we recommend.

Turn on 2FA

We support TOTP authenticator apps. Strongly recommended for any account with a Treasure Map.

Keep your PIN with your original will

Tape it inside the same envelope. Executors need both the registry code and the PIN to start the unlock flow.

Refresh your executor contact yearly

People move and change emails. The annual renewal email is your nudge to confirm your executor is still reachable.

Use FraudGuard for fast-lane login

If you've set up FraudGuard, sign in here with the same identity assertion. Optional, not required.

Compliance & partners

Read our privacy policy or just start.

The will registry is free. If you change your mind later, your data is yours to export or delete.

Security first, always.
Privacy by default.
Contact us