Security
Your estate plan contains some of the most sensitive information in your life. Here is how we protect it.
Passwordless Authentication
Sign in with a code sent to your email, or with Google. No passwords to steal, leak, or forget. Powered by Clerk, an enterprise-grade identity provider.
Encryption in Transit & at Rest
All data is encrypted in transit via TLS 1.3 and at rest using AES-256 encryption on our database servers. Your data is never stored in plain text.
Row-Level Security
Every database query is scoped to your user ID through Supabase Row-Level Security policies. Even if a bug exposed an API, it could not return another user's data.
Client-Side Vault Encryption
Vault items (passwords, recovery codes, sensitive notes) are encrypted in your browser before reaching our servers. We store only encrypted blobs, so we cannot read your secrets.
Data Ownership
Your data belongs to you. You can export everything at any time. If you delete your account, your data is permanently erased within 30 days.
Infrastructure
Hosted on Supabase (PostgreSQL) with automatic backups, point-in-time recovery, and infrastructure managed in SOC 2 compliant data centers.
Our Security Principles
Minimum data: We only collect what is necessary to provide the Service. We do not harvest data for ads or analytics beyond what is needed to improve the product.
Minimum access: Members you invite see only what you explicitly share with them. Permission levels (Owner, Editor, Viewer) control access granularly.
Defense in depth: Security is layered: authentication, authorization, encryption, network isolation, and audit logging each provide independent protection.
Responsible Disclosure
If you discover a security vulnerability, please report it to security@aftrmi.com. We take all reports seriously and will respond within 48 hours. Please do not publicly disclose vulnerabilities before we have had a chance to address them.
Questions?
For security-related questions, contact us at security@aftrmi.com.