Demo host · try the fictional Mitchell household · marketing pages only

Security architecture

Built so a financial institution could trust it with a household.

My Family Office holds the whole picture of a family’s financial life. Security is not a feature page we bolted on — it is how the product is built: isolation, encryption, mandatory two-factor, an AI that cannot move money, and an audit trail you can check.

Honest about certifications: we are not SOC 2 certified and have not yet published a third-party pen-test letter. The architecture below is what ships today; the roadmap is labeled as such.

How it fits together

Layers of protection around one household.

From the browser in, every request is treated as untrusted until identity, household scope, and (for money) a human approval are proven.

Security architecture diagramFive layers: you in the browser, TLS and web protections, identity with mandatory two-factor, the household vault with encryption and audit, and Diana as read-only with human approval for payments.YOUBrowser · TLS in transitEDGECSP · CSRF · rate limits · secure cookiesIDENTITYPassword + mandatory 2FA · passkeys & authenticatorHOUSEHOLD VAULTPer-household isolation · envelope encryption · hash-chained auditDiana · read-only · owner confirms every payment
Untrusted at the edge → proven identity → scoped to one household → AI that cannot move money.

In the product today

Architecture you can hold us to.

Your household is its own vault

Every record belongs to one household. Queries, file access, and Diana’s answers are scoped to that household alone — with automated tests that try (and fail) to reach another family’s data.

Encrypted with your own key

Documents, bank tokens, and MFA secrets are sealed with AES-256-GCM using a data key unique to your household (envelope encryption). Keys can be rotated. Production is designed for cloud key management — not a shared free-for-all.

Two factors, every sign-in

A password alone never opens the account. You use an authenticator app or a passkey (Face ID, Touch ID, Windows Hello, or a security key), with text or email codes available. Lockout after repeated failures.

A tamper-evident audit trail

Sign-ins, approvals, shares, and settings changes are written to a hash-chained audit log. Entries cannot be quietly edited; the owner can see the integrity check in the app.

Diana reads. She does not act.

Diana answers from your household’s records and never moves money or gives investment advice. Follow-ups she drafts wait for an owner’s confirmation before anything goes out.

Bill pay is prepare-only

Bills become drafts. An owner must confirm amount, payee, and funding account before anything pays. If a payee’s bank details change, payments stop until you re-approve.

Uploads are inspected, not trusted

Files are size-capped, type-checked by content (not just the filename), and served with sandboxing headers. Risky types download only — they do not run in the browser.

Hardened by default on the web

Strict Content Security Policy with per-request nonces, CSRF protection, rate limits, and secure cookies (__Host-, HttpOnly, Secure, SameSite) on every session.

What this means for you

Plain English, not a threat model.

You should not need a security questionnaire to understand the basics. Here is what the architecture buys a household owner day to day.

  • Another household cannot see your balances, documents, or bills.
  • Nothing sensitive opens on a password alone — a second factor is required every time.
  • Diana can prepare a review; she cannot pay a bill or change a bank.
  • You can see who signed in, who approved a payment, and whether the audit trail is intact.
  • A look-alike site cannot steal a passkey; passkeys are bound to this origin.
  • We do not claim certifications we do not hold — see the roadmap below.

Roadmap · how we build

Bank-grade means finishing the real-world steps too.

Code alone does not make a SOC 2 report or a pen-test letter. These items are on our path; we do not pretend they are done.

Coming

Independent penetration test

Annual third-party review by a qualified firm, with remediation and re-test.

Coming

SOC 2 Type II

Controls are mapped and the product is built for SOC 2 readiness. We are not SOC 2 certified yet — that requires an independent auditor and an observation window.

Coming

Cloud KMS for master keys

The encryption layer already supports a pluggable key provider. Moving master keys into a cloud KMS or HSM is the next custody step.

Coming

Institutional SSO

SAML or OIDC for family offices and banks that need joiner–mover–leaver control through their own identity provider.

Open a household on this foundation.

Two-factor before the app opens. Encrypted vault. Diana ready when the record starts to fill in — and never authorized to move money.