Security

Built around permission, proof, and release rules

Your most private information deserves more than a password box. DoneAfter is engineered so nothing sensitive is released without the right trigger, the right approvals, and a complete audit trail — and a single missed check-in never dumps your data.

Four pillars

Security is layered across transport, storage, people, and proof.

Encryption

HTTPS everywhere, encryption at rest for sensitive fields and files, and hardened password hashing with Argon2id.

Access Control

Role-based access plus per-item permissions. Trusted contacts see only their assigned role — never your full plan.

Audit Logs

Every sensitive action is recorded in an append-only audit trail for accountability and review.

Private Storage

Uploaded documents live outside the public web root and are served only through signed, expiring links.

Verification seal and badge
Verification Center

Release only after proof

Trusted contacts submit triggers and evidence; staged release and multi-party approvals gate what goes out.

  • Death, incapacity, and event-based triggers
  • Evidence upload with admin review
  • Staged levels: emergency only → limited family → business → full verified
  • One- or two-person approvals for the most sensitive items
  • Waiting periods and secure-link-only delivery

Safety features

Layered protections across your whole plan.

Two-Factor Authentication

Add TOTP-based 2FA to protect your account beyond a password.

Trusted Contact Verification

Contacts confirm their identity before they can act on your behalf.

Dead Man's Switch Safety

A missed check-in triggers gentle escalation — never an automatic data dump.

Rate Limiting & Throttling

Login and emergency-code attempts are throttled to resist brute force.

Secure Access Links

Sensitive content is delivered via expiring signed links, never emailed directly.

Data Export & Deletion

Export your data or request deletion — you stay in control of your information.

CSRF, XSS & SQLi defenses

Session CSRF tokens, output escaping, and prepared statements are baseline — not optional.

Admin accountability

Restricted admin access to private content requires justification and is audit-logged.

Letter mail review

After-death physical letters require verified trigger plus human review before mailing.

Please read

Sensitive credentials & seed phrases

By default, DoneAfter stores instructions and locations, not raw passwords or crypto seed phrases.

  • We do not recommend uploading raw seed phrases anywhere online
  • Use hardware wallets, multisig, and split-key approaches for crypto
  • If you must store something highly sensitive, expect extra warnings and confirmations
  • Sensitive instructions should be reviewed by an attorney
Read the Security Policy Crypto guidance
Hardware security key

Have a security question or want to report a vulnerability? Contact our team.