Privacy First
Your Financial Data, Protected By Design
Khair Labs cannot read your estate. Your data is encrypted under a key that only your password or Estate Passphrase can unlock, AI processing stays off by default, and every action is logged in a tamper-evident audit trail. Decryption happens only inside your own unlocked, authorised session — never on an admin screen, and never by us.
Architecture
Encrypted By Design
Four layers of protection keep your data private at every stage: from entry to storage to AI processing.
AES-256-GCM Encryption
Every document, asset value, and family detail is encrypted with AES-256-GCM before it is written to the database, sealed under a key only your password or Estate Passphrase can unlock. It stays unreadable at rest and in transit. We're still confirming with our hosting provider whether their own infrastructure-level backups are covered the same way, so we're not making that claim yet.
Your Key, Not Ours
Your encryption key is derived from your password (or your Estate Passphrase, for SSO accounts): never from a key we hold. Khair Labs cannot derive it and cannot read your estate; decryption happens only inside your own unlocked, authorised session.
AI Processing Is Opt-In
ORIS AI, operated by Khair Labs at api.meetoris.com (which selects the underlying model), sees your family, asset, and calculation details only after you switch on "ORIS AI Processing" in Settings, off by default. Phone numbers, emails, Aadhaar, PAN and account numbers are pattern-redacted before anything is sent; names and amounts are not, since the advisory features need them.
Hash-Chain Audit Trail
Every action is logged in an immutable, tamper-evident audit trail. Each entry is cryptographically linked to the previous one using SHA-256 hashing; any tampering breaks the chain and is instantly detectable.
Transparency
Complete Visibility Into Our Access
We believe you should know exactly what we can and cannot see. There are no grey areas.
What Khair Labs Cannot Read
- Your asset values and property details
- Bank account and FD information
- Family financial arrangements
- Inheritance calculation amounts
- Bequest details and beneficiary finances
Encrypted under a key only your password or Estate Passphrase unlocks. Khair Labs cannot derive that key and cannot read these values; there is no admin or support tool that decrypts them.
What Wasiyat Can See
- Your email address (for login)
- Subscription tier and billing status
- Anonymous usage analytics (if you consent)
- Feature usage patterns (anonymized)
Minimal data needed for authentication and platform operation. Never sold to third parties.
The Honest Version
How Your Data Is Protected
“Khair Labs cannot read your estate” is a strong claim, so here is exactly what it does and doesn't cover.
Decryption happens in memory, only during an authorised session
Your key is unwrapped on our server only while you (or a delegate you've authorised) are actively signed in and unlocked. It is never written to disk in plaintext, and nothing decrypts on a schedule, in the background, or on an admin screen.
A few structural facts stay readable
Facts our calculation engine needs without your key open (relationships, dates, status flags) plus your account identity (name, email, billing) are not sealed under your key. See “What Wasiyat Can See” above for the full list. A small number of older Amanah Register notes and item locations are still being migrated onto this scheme; until that finishes, they remain protected the way our records always have been: encrypted, but under a system-held key rather than yours. Your Incapacity Card's AMD copy location and power-of-attorney pointer stay on that same system-held-key protection permanently and by design, not as a migration gap: they're shown to a confirmed emergency contact who has no Wasiyat login, so they have to be readable without your key.
Vault documents, video messages, and family photos are on an older protection scheme
Files you store in the Vault, your Nasihah letters and video messages, and photos you attach to a family member, predate your password/passphrase-derived key and are not sealed under it: Vault files and Nasihah content are encrypted under a system-held key our server can decrypt to serve them to you, your delegates, or (after your death) your authorised executor and recipients — which is how the delivery in the first place is possible; family photos are stored as uploaded, without encryption, behind the same access controls as the rest of your account. All of these are on our roadmap to move onto your key; until then, treat this page's “Khair Labs cannot read your estate” claim as covering your estate DATA — family, assets, calculations, bequests, and the documents we generate from them — not files, recordings, or photos you upload yourself.
A short staging window at claim time
When your executor's death claim is approved, the recipient names, contact details, and delivery links for your video messages and notices are held server-side for up to 7 days so they can actually be sent, then permanently deleted. This is a deliberate, time-boxed exception to “never readable server-side” for that specific data — on top of the Vault/photo and migration exceptions described above, which are ongoing rather than time-boxed.
If everything is lost, your data is gone, permanently
Lose your password, your recovery key, and every delegate you've named, and there is no way back in: not for you, not for us. We hold no master key that could recover it. That is what makes the rest of this page true, not a bug in it.
A revoked link works until you rotate your key
Revoking a delegate stops new access immediately, but if they kept a copy of an old link, it can still open what it covered until you rotate your encryption key (a feature we're still building). Revoke promptly, and treat old links as sensitive until rotation ships.
Compliance
DPDPA 2023 Ready
Built to align with India's Digital Personal Data Protection Act. Your rights are not just respected; they are built into the platform.
Consent Management
Consent controls for AI processing, professional referral, marketing, and analytics let you decide what we do with your data; each is independent and revocable at any time. Estate planning and document storage are required to use the service.
Data Portability
Export all your data anytime in PDF and JSON formats. Your family tree, asset inventory, calculation history, and documents: everything you created belongs to you and can leave with you.
Right to Erasure
Request deletion of your account and personal data from your privacy settings. Personal data is erased within 30 days, and encrypted vault contents become unrecoverable once your encryption context is removed. Records we are legally required to keep, such as financial records under the Income Tax Act, are retained. Death-claim proof documents (such as an uploaded death certificate) are a current exception, not yet covered by this automated process — see our Privacy Policy for how to request their removal separately.
Under the Hood
Technical Deep-Dive
For the technically inclined, here is exactly how your data flows through our system.
// Data encryption pipeline
Your Data → AES-256-GCM (your key) → Encrypted Storage
// Key derivation
Your Key = scrypt(your password or Estate Passphrase, salt)
Recovery = one-time key you hold, shown to you once
Delegates = wrapped copies you issued to people you trust
// AI query path
AI Query → Consent Check → Pattern Redactor → ORIS AI
// Immutable audit chain
Audit Log → SHA-256(previous_hash + entry) → Immutable Chain
When you request deletion, your account is deactivated immediately and your team-processed request removes the wrapped keys that unlock your estate; once that happens, the encrypted data cannot be recovered by anyone, including us.
Defense in Depth
Multiple Layers of Protection
Security is not a single feature; it is a culture embedded in every layer of Wasiyat.
Security Headers
CSP, HSTS, X-Frame-Options, and X-Content-Type-Options are enforced on every response. Clickjacking, XSS, and MIME-sniffing attacks are blocked at the infrastructure level.
TOTP Two-Factor Auth
Optional TOTP-based 2FA using any authenticator app (Google Authenticator, Authy, Microsoft Authenticator). Your second factor never leaves your device.
Bcrypt Password Hashing
Passwords are hashed with bcrypt at cost factor 12, computationally expensive enough to resist brute-force attacks while remaining fast for legitimate login.
Short-Lived JWT Tokens
Authentication uses JWT tokens with short expiration windows, verified using the jose library for Edge Runtime compatibility. Sessions are Redis-backed for instant revocation.
Document Integrity
Every generated document is protected by SHA-256 hashing and carries a unique Wasiyat Document ID (DIN). Confirm instantly that a document was generated by Wasiyat and hasn't changed since issuance, via QR code or the public verification portal.
Minimal Data Collection
We collect only what is necessary for estate planning functionality. No advertising or cross-site tracking, no selling data to third parties. Optional first-party product analytics, only with your consent.
Start Your Secure Estate Plan
Your financial data deserves the highest level of protection. Experience per-user encrypted estate planning with a 14-day free trial.
No credit card required. Your data is encrypted from day one.