Security

Built to hold the most sensitive things a household has.

FamilySafe keeps passwords, documents and final wishes in one place. That only works if the security is honest, specific and verifiable. Here is exactly how your information is protected, and how we hold ourselves to account.

UK Sovereign Hosted · GDPR-compliant · zero-knowledge encryption
Security posture
Zero-knowledge encryptionIn product
UK data residencyLive
ICO registeredLive
Cyber Essentials PlusIn progress
ISO 27001In progress
How we protect your data

Six controls that sit under everything you store.

Zero-knowledge by design

Documents and sensitive fields are encrypted before they leave your device. We hold the infrastructure, not your keys, so we cannot read your content.

Encrypted in transit and at rest

Everything moves over modern TLS and is stored encrypted. Files are encrypted individually, not just the disk they sit on.

UK data residency

Your data is hosted in the United Kingdom on GDPR-compliant infrastructure, and does not leave UK jurisdiction in normal operation.

Role-based access

Sharing is permission-led. A partner might see everything, an adviser only the financial section. You grant and revoke access at any time.

Multi-factor authentication

Accounts are protected with MFA, and trusted-contact verification gates the moments that matter, like Probate access.

Audited access logs

Every access to a shared record is logged and visible to you. You can see who reached what, and when, with nothing hidden.

End-to-end, in plain English

What happens to a document when you add it.

Encryption is easy to claim and hard to verify. So here is the path a file actually takes, from your hand to UK storage, with nothing readable in between.

01

On your device

You add a passport scan or a policy. It is encrypted locally, on your device, before anything is sent.

02

In transit

The already-encrypted file travels over modern TLS. Anyone intercepting it sees ciphertext, not your document.

03

At rest, in the UK

It is stored encrypted on UK infrastructure. We can hold it and move it, but we cannot open it. Only your keys can.

Your control

You decide who sees what, and you can change your mind.

Security is not only about keeping people out. It is about giving the right people the right access, on your terms, and letting you take it back.

Granular sharing

Share a whole record, a single section, or one document. Access is scoped to exactly what each person needs.

Revoke anytime

Permissions are not permanent. Withdraw access in a tap, and the change takes effect immediately.

Conditional emergency access

Nominees reach what you have chosen only when the conditions you set are met. Until then, it stays closed.

Export and delete

Your data is yours. Export it in standard formats, or delete your record entirely, at any time.

Standards & accountability

We state our certifications by status, never before they are granted.

Trust is earned in public. Each item below is shown with its real status. We will update this page as certifications are awarded, not before.

ICO registered
Live · ZC157853
Cyber Essentials Plus
In progress
ISO 27001
In progress
Zero-knowledge encryption
In product
Data residency
United KingdomGDPR-compliant hosting
Data protection
ICO registeredReg. ZC157853
Accountable entity
FamilySafe LtdHalifax, West Yorkshire
Encryption
Zero-knowledgeIn transit & at rest

Certifications are displayed by status and are never shown as certified before they are granted. Registration and VAT numbers are placeholders until confirmed for publication. ISO 27001 is on the roadmap and is not yet certified.

Responsible disclosure

Found a vulnerability? Tell us, and we will act.

We welcome reports from security researchers and customers. Email our security team with the details and steps to reproduce. We aim to acknowledge every genuine report and keep you updated as we investigate.

Disclosure policy, scope & PGP key to be published before launch
What to include
  • A clear description of the issue
  • Steps to reproduce it
  • The impact you think it has
  • How we can reach you
Security questions

Honest answers to the questions people ask first.

Can FamilySafe staff read what I store?
No. Documents and sensitive fields are encrypted before they leave your device, using a zero-knowledge architecture. Our team holds the infrastructure, not your keys, so we cannot read your content. Even under a valid legal request, we can only provide encrypted data we are unable to open.
Where is my data stored?
In the United Kingdom, on GDPR-compliant infrastructure. Your data does not leave UK jurisdiction in normal operation, and our accountable entity, FamilySafe Ltd, is registered in England and Wales with a registered office in Halifax.
What happens if I lose my password?
Because of zero-knowledge encryption, we cannot reset access to encrypted content on your behalf. During onboarding you set up recovery using a recovery key and your nominated trusted contacts, so you are never locked out, and we are never able to open your record for someone who should not have it.
Is my information encrypted on my phone?
Yes. Sensitive content is encrypted on the device before it is stored or synced. Combined with your device's own lock, this means a lost or stolen phone does not expose your record.
How is Probate access kept secure?
Nominees can only reach what you have explicitly chosen to share, and only when the conditions you set are met. Access requests are verified, logged and visible to you. Until your conditions are satisfied, the record stays closed.
Start today

Security you can read, not just trust.

Get your household in order on infrastructure built to hold it. Free to start, no credit card.

Try it nowTalk to us