Privacy First
Your Financial Data Is Invisible — Even to Us
Wasiyat is built on a zero-knowledge architecture. Your estate data is encrypted before it reaches our servers, your AI queries are stripped of personal information, and every action is logged in a tamper-proof audit trail. We designed it this way because estate planning demands absolute trust.
Architecture
Zero-Knowledge by Design
Four layers of protection ensure your data remains private at every stage — from entry to storage to AI processing.
AES-256-GCM Encryption
Every document, asset value, and family detail is encrypted with military-grade AES-256-GCM before it touches our servers. Data is unreadable without your unique key — at rest, in transit, and in backups.
Per-User Encryption Keys
Your encryption key is derived from your identity. Each user gets a unique Data Encryption Key (DEK) wrapped by a master Key Encryption Key (KEK). Even our database administrators cannot decrypt your data.
PII Redaction in AI
When ORIS AI processes your queries, all personally identifiable information is automatically stripped. Names, Aadhaar numbers, bank details, property addresses — redacted before reaching any AI model.
Hash-Chain Audit Trail
Every action is logged in an immutable, tamper-evident audit trail. Each entry is cryptographically linked to the previous one using SHA-256 hashing — any tampering breaks the chain and is instantly detectable.
Transparency
Complete Visibility Into Our Access
We believe you should know exactly what we can and cannot see. There are no grey areas.
What Wasiyat Cannot Access
- Your asset values and property details
- Bank account and FD information
- Family financial arrangements
- Vault document contents
- Inheritance calculation amounts
- Bequest details and beneficiary finances
Encrypted with your per-user key. Mathematically inaccessible to Wasiyat staff, even under compulsion.
What Wasiyat Can See
- Your email address (for login)
- Subscription tier and billing status
- Anonymous usage analytics (if you consent)
- Feature usage patterns (anonymized)
Minimal data needed for authentication and platform operation. Never sold to third parties.
Compliance
DPDPA 2023 Compliant
Fully aligned with India's Digital Personal Data Protection Act. Your rights are not just respected — they are built into the platform.
Consent Management
Six granular consent controls let you decide exactly what data we collect and how we use it. Analytics, marketing, AI processing, document storage — each toggle is independent and revocable at any time.
Data Portability
Export all your data anytime in PDF and JSON formats. Your family tree, asset inventory, calculation history, and documents — everything you created belongs to you and can leave with you.
Right to Erasure
Delete your account and all associated data permanently. We use cryptographic erasure — your encryption key is destroyed, rendering all encrypted data mathematically unrecoverable within 24 hours.
Under the Hood
Technical Deep-Dive
For the technically inclined — here is exactly how your data flows through our system.
// Data encryption pipeline
Your Data → AES-256-GCM (your key) → Encrypted Storage
// Key derivation
Your Key = SHA-256(MASTER_SALT + your_user_id)
// AI query redaction
AI Query → PII Redactor → Anonymized Query → Claude AI
// Immutable audit chain
Audit Log → SHA-256(previous_hash + entry) → Immutable Chain
Envelope encryption ensures that destroying a single key renders all user data permanently unrecoverable — enabling true cryptographic erasure.
Defence in Depth
Multiple Layers of Protection
Security is not a single feature — it is a culture embedded in every layer of Wasiyat.
Security Headers
CSP, HSTS, X-Frame-Options, and X-Content-Type-Options are enforced on every response. Clickjacking, XSS, and MIME-sniffing attacks are blocked at the infrastructure level.
TOTP Two-Factor Auth
Optional TOTP-based 2FA using any authenticator app (Google Authenticator, Authy, Microsoft Authenticator). Your second factor never leaves your device.
Bcrypt Password Hashing
Passwords are hashed with bcrypt at cost factor 12 — computationally expensive enough to resist brute-force attacks while remaining fast for legitimate login.
Short-Lived JWT Tokens
Authentication uses JWT tokens with short expiration windows, verified using the jose library for Edge Runtime compatibility. Sessions are Redis-backed for instant revocation.
Document Integrity
Every generated document is protected by SHA-256 hashing and carries a unique DIN (Document Identification Number). Verify authenticity instantly via QR code or the public verification portal.
Minimal Data Collection
We collect only what is necessary for estate planning functionality. No behavioural tracking, no advertising, no selling data to third parties. Your privacy is our product, not your data.
Start Your Secure Estate Plan
Your financial data deserves the highest level of protection. Experience zero-knowledge estate planning with a 14-day free trial.
No credit card required. Your data is encrypted from day one.