Our Absolute Commitment to Your Privacy
Our commitment to your privacy is absolute.
We understand the hesitation. Handing over intimate family letters and private journals requires absolute trust. We are entirely candid with you: we are in the business of preserving your legacy.
Our platform is built on AWS infrastructure with AES-256 encryption, strict access controls, and automated data lifecycle management.
AES-256 Encryption Standard
Every document you upload is secured in transit (TLS 1.2+) and at rest. 100% of our storage infrastructure uses AES-256 encryption via AWS Server-Side Encryption.
Auto-deleted after 7 days
Once your final narrative is generated and delivered, your source files are permanently scrubbed from our systems. Your legacy belongs to you, not our servers.
Zero Data Retention
We don't train our AI on your family's history. Your grandparents' letters will never become part of a public language model. We use state-of-the-art technology to translate and structure your history. The data remains completely private.
Let us be unequivocal about the technology we use: Zero Data Retention. We don't train our AI on your family's history. The data remains completely private.
The Evidence Behind Our Promise
Security Architecture
Our platform is designed to align with industry security frameworks including ISO/IEC 27001 and SOC 2 principles. Our technical controls are modeled on Annex A requirements.
- A.8.24 Cryptography: 100% of storage buckets verified encrypted at rest (AES-256).
- A.8.12 Data Leakage Prevention: All storage has Public Access Block enforced.
- Audit Logging: AWS CloudTrail records API and management actions across the platform.
- Threat Detection: AWS GuardDuty enabled for anomaly detection and security monitoring.
- A.8.2 Access Management: Root MFA active, key rotation within 90-day policy.
- A.7.1 Network Perimeter: Zero administrative ports (SSH/RDP) open to the public internet.
- Vendor Management: Strict vetting of all sub-processors (AWS, Stripe).
End-to-End Encryption (SSE-S3)
Your data is encrypted not just in transit, but at rest using Server-Side Encryption with Amazon S3-Managed Keys (SSE-S3).
At Rest
All files in S3 and metadata in DynamoDB are encrypted with AES-256 using a key strictly isolated from general employee access.
Access Controls
Administrative access is restricted via IAM least-privilege policies. Encryption keys are managed by AWS and isolated from application-level access.
7-Day Auto-Deletion Policy (Digital Shredder)
We believe the safest data is data we no longer hold. Our "Digital Shredder" policy is enforced by immutable infrastructure code using S3 Lifecycle Policies.
All source documents uploaded to our system are automatically and permanently deleted 7 days after upload.
Note: This applies to your raw uploads. Your generated final dossier is securely retained for your access, or hosted publicly if you opt into the Heritage Vault.
Opt-In Public Hosting (Heritage Vault)
While your data is secure by default, we understand that family history is meant to be shared. The Heritage Vault is an opt-in service that hosts your finalized dossier as a public, shareable website.
By clicking "Share with Family" and subscribing to the Heritage Vault ($4.99/mo after a 7-day trial), you are intentionally moving your finalized dossier into an open S3 environment. This specific link is not password-protected and is accessible to anyone who possesses it. You may cancel your subscription to revoke public access at any time, which automatically seals the archive.
Ready to arrest time?
Your family's legacy is safe with us. Start preserving their stories today.
Start Your Archive