Back to Blog

Security

How We Protect Your Data

Your family's privacy is important to us. We use end-to-end encryption so that only you and your household members can read your data.

End-to-End Encryption

Sensitive information you store in EstateHelm is encrypted on your device before it reaches our servers.

Your Keys, Your Control

Your data is encrypted with keys that only your devices can access. We don't have access to your encryption keys.

Zero-Knowledge Design

We store your encrypted data, but we can't read it. Only your registered devices can decrypt it, protected by biometrics when available.

AES-256-GCM Encryption

We use AES-256-GCM, a well-established encryption standard used across the industry.

Biometric Authentication

We use WebAuthn with your device's biometric security (Face ID, Touch ID, or Windows Hello) to derive your encryption keys:

How It Works

  • Biometric unlock — Face ID, Touch ID, or Windows Hello authenticates you
  • Key derivation — A unique encryption key is derived using WebAuthn PRF
  • Device-bound — Keys are tied to your specific device and biometrics

Supported Platforms

  • Apple devices — Face ID or Touch ID via WebAuthn PRF
  • Windows — Windows Hello (fingerprint, face, or PIN)

Recovery Key

Since encryption keys are device-bound, you need a backup way to recover your data:

One-time recovery key

During setup, you receive a recovery key. Keep it somewhere safe.

Your responsibility

Write it down or store it in a password manager. We cannot recover it for you.

Use it to add new devices

Your recovery key lets you set up EstateHelm on a new device if you lose access to your current one.

How It Fits Together

Your data is protected by multiple layers:

Your Household Data (contacts, documents, etc.)
↓ Encrypted with household keys
Household Keys (General, Financial, Security)
↓ Encrypted with your master key
Your Master Key (AES-256)
↓ Derived from biometric authentication
Face ID / Touch ID / Windows Hello
+ Recovery Key (backup)

What This Means For You

Privacy

We can't read your contacts, financial information, or documents

Secure sharing

When you invite family members, they get their own encrypted access

No data mining

We can't analyze or share your information because we can't see it

Your responsibility

Keep your recovery key safe. If you lose your device and your recovery key, we cannot recover your data.

Ready to secure your household data?

Start using EstateHelm today with our industry-leading encryption.

Get Started Free