Loading VanshEra
Loading VanshEra
· Security & Trust
You are trusting us with a map of everything your family owns. You deserve plain answers, not legal fog.
Every document is encrypted in your browser (AES-256-GCM) with a key derived from your vault passphrase before it is uploaded. Under normal operation our servers only ever receive and store ciphertext — not your documents and not your vault key — so a database breach yields unreadable blobs.
We want to be precise rather than absolute: because VanshEra delivers the web/app code that does the encryption, a compromise of that code, of your browser, or of your device could in principle expose documents while your vault is unlocked. That is the honest boundary of any in-browser encryption. We harden it by shipping no third-party scripts on vault pages, a content-security policy (moving to a stricter nonce-based one before public launch), and protected deployment access.
Full account, folio and policy numbers are encrypted at rest with a separate server-side key, and the app shows them masked (••••1234). Full numbers appear only where they are needed: in password-protected exports, in the executor preview, and to your executor and designated family after a verified release — so our application can decrypt them where a feature needs it. What our systems can see in readable form: your name, email, phone, institution names, asset types, nominee names and the valuations you enter — what is needed to compute your net worth and readiness score.
We cannot reset it — that is the price of real encryption. Instead, you choose trusted people who each hold a recovery share; the number of them who must come together (e.g. any 3 of 5) is your choice. You can also print an offline Emergency Recovery Kit. Both work without VanshEra's help.
Three protections: your registry exports in full at any time (JSON, ZIP or PDF), and vault documents download one at a time — exports never contain vault documents, so keep your originals; your printed Recovery Kit and recovery shares rebuild your vault key without us; and in a wind-down we would give advance notice and an extended export window before any deletion, so you have time to download everything.
An attacker who stole our entire database would get: encrypted document blobs they cannot open, encrypted account numbers, and hashed passwords (bcrypt) and hashed tokens. What they would get in readable form is the same limited metadata we can see — names, emails, institution names, valuations. Painful, but your documents and full account numbers stay sealed. We fail-closed by design.
Nothing releases automatically on a single report. A release needs the quorum of trusted contacts you chose (at least two, each verified and on file for 72 hours), your chosen waiting period (7–90 days), a death-certificate check by a person at VanshEra (today, the founder), and a final 7-day warning to you by email (SMS and WhatsApp are not live yet). At any point, signing in and confirming your password (“I'm alive”) freezes everything; a sign-in alone, or the emailed check-in link, does not. You can also configure the proof-of-life schedule yourself.
On encrypted infrastructure hosted with Vercel and Neon (currently in Singapore; a move to Indian data centres is planned before public launch). All traffic is TLS-encrypted. Payments, when they launch, will be handled by an RBI-regulated processor — we will never store card numbers.
Export your registry (JSON, ZIP or PDF) and download your vault documents one at a time, then email hello@vanshera.com from your registered address and we will delete your account and data. No lock-in, no dark patterns.
Questions we haven't answered? hello@vanshera.com