Keystead Vault
Security & Trust

Your vault holds what matters most. Here’s exactly how we protect it.

Keystead Vault keeps the records a business would need to keep running if the owner couldn’t be there — tax details, key contacts, insurance, and instructions. That’s sensitive by nature, so we built the security in from the first line of code, not bolted on after. This page is a plain, specific account of how it works.

Last updated: August 3, 2026

How your data is protected

Isolated at the database

Every vault is walled off by row-level security enforced inside the database itself — a separate layer from the app, so one customer’s account can’t be served another’s data even if the app’s own checks failed. We re-verify this with an automated access-control test suite as the product changes.

Encrypted in transit & at rest

All traffic runs over HTTPS with strict transport security (HSTS), so browsers refuse to connect any other way. Your stored data and file uploads are encrypted at rest by our infrastructure providers.

Sign-in you control

Authentication is handled by a dedicated identity provider. Passwords are salted and hashed — never stored in plain text, and never visible to us. Email confirmation is required, and it’s enforced at the database, not just the interface.

You decide who sees it

Sharing is explicit and per-person — an advisor, a successor, a co-owner, or a whole firm by email domain. A successor can open only the calm “start here” view, never the full vault — a limit enforced at the database — until an owner or an editor (such as your CPA) promotes them to full access. That’s how a firm hands the vault off to your successor if you’re gone. You — or anyone you’ve made an editor — can change or revoke access at any time; only the owner can be neither removed nor demoted, and every access change is recorded in the activity log with who made it.

One thing to know about firm-by-domain access: it covers everyone who signs in with a confirmed email at that domain, for as long as the grant is in place. If someone leaves that firm but keeps a working email at the domain, they keep access until the firm removes their mailbox or you remove the firm grant. For a departing relationship, remove the firm grant (or switch to inviting people individually).

The passwords we never hold

A vault is only safe if it isn’t itself a honeypot.

Keystead stores directions to where a login lives — “the bank login is in 1Password under ‘Operating Account’” — not the passwords themselves. We deliberately don’t become a single place where every credential to your business sits waiting to be stolen. A successor learns how to get in; the actual secrets stay in your password manager.

Sensitive documents & AI

When you upload a tax return so we can fill in the details for you.

Before any AI ever sees the text, our server strips Social Security numbers and account numbers from it. The AI receives only redacted text, it’s used solely to read fields for that one upload, and you review everything it extracted before anything is saved. We don’t use your data to train AI models.

Payments

Billing is handled by Stripe, a certified PCI Service Provider. We never see or store your card number — it goes straight to Stripe. Keystead is a US-only service, and that’s enforced at checkout.

A record of every change

Each edit to a vault is recorded with who made it and when, in an append-only log — it can’t be edited or rewritten through the app. So a successor or advisor can always see the history of what changed.

Our promises to you

Who helps us run Keystead (subprocessors)

We use a small set of established providers, each vetted for security. Full list in our Privacy Policy.

ProviderWhat they do
SupabaseDatabase, authentication, and encrypted file storage
RenderApplication hosting
StripePayment processing (we never see card numbers)
AnthropicAI reading of redacted tax-return text for auto-fill
ResendSending transactional email (reminders, confirmations)
SentryError monitoring to catch and fix problems

Where we are on formal certification

We hold ourselves to the SOC 2 Trust Services Criteria and run an ongoing internal readiness assessment, plus automated security tests (access-control, injection, and content-security) that we re-run as the product changes. We plan to engage an independent, third-party security review before taking on customers at scale. To be straight with you, we have not undergone a SOC 2 audit or an independent security review yet — and we’ll say so plainly here until we have, rather than imply a certification we don’t hold.

What we ask of you

Security is shared. Please use a strong, unique password for your account, keep the device you sign in from secure, and only invite people you genuinely trust. Share access at the lowest level that gets the job done — a viewer for someone who only needs to look.

Found a security issue?

We take reports seriously and won’t pursue good-faith researchers. Email security@keysteadvault.com with the details and we’ll respond quickly. For anything else, reach us at support@keysteadvault.com.

This page describes our security practices as of the date above and is provided for transparency. It is not a warranty, a contract, or a security certification. Our practices evolve as the product does, and we’ll update this page accordingly.