Your household is its own vault
Every record belongs to one household. Queries, file access, and Diana’s answers are scoped to that household alone — with automated tests that try (and fail) to reach another family’s data.
Security architecture
My Family Office holds the whole picture of a family’s financial life. Security is not a feature page we bolted on — it is how the product is built: isolation, encryption, mandatory two-factor, an AI that cannot move money, and an audit trail you can check.
Honest about certifications: we are not SOC 2 certified and have not yet published a third-party pen-test letter. The architecture below is what ships today; the roadmap is labeled as such.
How it fits together
From the browser in, every request is treated as untrusted until identity, household scope, and (for money) a human approval are proven.
In the product today
Every record belongs to one household. Queries, file access, and Diana’s answers are scoped to that household alone — with automated tests that try (and fail) to reach another family’s data.
Documents, bank tokens, and MFA secrets are sealed with AES-256-GCM using a data key unique to your household (envelope encryption). Keys can be rotated. Production is designed for cloud key management — not a shared free-for-all.
A password alone never opens the account. You use an authenticator app or a passkey (Face ID, Touch ID, Windows Hello, or a security key), with text or email codes available. Lockout after repeated failures.
Sign-ins, approvals, shares, and settings changes are written to a hash-chained audit log. Entries cannot be quietly edited; the owner can see the integrity check in the app.
Diana answers from your household’s records and never moves money or gives investment advice. Follow-ups she drafts wait for an owner’s confirmation before anything goes out.
Bills become drafts. An owner must confirm amount, payee, and funding account before anything pays. If a payee’s bank details change, payments stop until you re-approve.
Files are size-capped, type-checked by content (not just the filename), and served with sandboxing headers. Risky types download only — they do not run in the browser.
Strict Content Security Policy with per-request nonces, CSRF protection, rate limits, and secure cookies (__Host-, HttpOnly, Secure, SameSite) on every session.
What this means for you
You should not need a security questionnaire to understand the basics. Here is what the architecture buys a household owner day to day.
Roadmap · how we build
Code alone does not make a SOC 2 report or a pen-test letter. These items are on our path; we do not pretend they are done.
Coming
Annual third-party review by a qualified firm, with remediation and re-test.
Coming
Controls are mapped and the product is built for SOC 2 readiness. We are not SOC 2 certified yet — that requires an independent auditor and an observation window.
Coming
The encryption layer already supports a pluggable key provider. Moving master keys into a cloud KMS or HSM is the next custody step.
Coming
SAML or OIDC for family offices and banks that need joiner–mover–leaver control through their own identity provider.
Two-factor before the app opens. Encrypted vault. Diana ready when the record starts to fill in — and never authorized to move money.