Security & privacy

Encrypted by default. Least-privilege by design.

Your BDBN, your beneficiaries, your documents — they belong to your family. Here's exactly what protects them today, and what's still on the roadmap.

Encryption

  • AES-256 for data at rest, including every vault document.
  • TLS 1.3 for every byte in transit.
  • Row-level security: every record is scoped to your account at the database level, so one account can never read another's data.
  • Signed, expiring links for document downloads and first-responder Medical ID access — no permanent public URLs.
  • On the roadmap: ML-KEM-768 (FIPS 203) post-quantum key exchange and client-side zero-knowledge vault keys. We'll say so here the day they're live — not before.

Data residency

All primary data storage is in Australian regions of the cloud provider. Backups are geo-redundant within Australia. No data is processed in jurisdictions that don't meet the Australian Privacy Act 1988 (APPs) minimums.

Access

  • Passkey / WebAuthn multi-factor authentication for every account.
  • Inner-circle access is time-boxed, granular, and revocable. You choose exactly which record each person can see, and for how long.
  • Emergency access requires a verified OTP flow with a mandatory waiting period.
  • All privileged operations are logged to an immutable audit trail.

Testing & assurance

  • Continuous automated dependency and code scanning.
  • Independent penetration testing on every major release.
  • SOC 2 Type II in progress; ISO 27001 on the roadmap.

Ready to get started?

Read the Trust Centre