Encrypted at rest and in transit
Every document is encrypted before it reaches storage using AES-256-GCM with a unique key. Data in transit is protected by TLS. Even if our storage were compromised, your files remain ciphertext.
Keepacy™ is built around encryption, access control, and compliance from the ground up — not bolted on as an afterthought.
All documents and sensitive fields encrypted with AES-256-GCM at rest.
Only you can access your vault while your account is active. Documents are released to beneficiaries only after verified death certification.
Time-based one-time passwords (TOTP) and passkey support for account access.
Full data export and deletion rights. We never sell your personal information.
Digital asset directive support per NY EPTL Article 13-A (RUFADAA). Content and catalogue consent recorded per beneficiary.
Continuously scanned against OWASP Top 10 vulnerability categories.
Security is not a feature we added — it is the foundation everything else is built on.
Every document is encrypted before it reaches storage using AES-256-GCM with a unique key. Data in transit is protected by TLS. Even if our storage were compromised, your files remain ciphertext.
Your documents are protected with strong encryption. Only you can access your vault while your account is active. In the event of your passing, after your beneficiaries have been verified through our death certificate or physician statement review process, Keepacy facilitates secure document release to your designated beneficiaries.
Before any beneficiary receives access, Keepacy runs a staged, multi-channel escalation over days to confirm you are unreachable. A single missed check-in never triggers a release.
All login attempts, document views, beneficiary changes, and vault releases are logged with timestamps and preserved for compliance. Beneficiary access audit trails are retained for 7 years.
Encryption Architecture
Your documents are protected by envelope encryption. Each document is encrypted with its own unique key, and multiple layers of key wrapping ensure your data remains secure at rest.
Your Password
Never stored anywhere
Key Encryption Key (KEK)
In-memory only, never persisted
Data Encryption Key (DEK)
Unique per document
Your Documents
Encrypted at rest in cloud storage
Expand any section below to see exactly how Keepacy implements each security control.
Start with the free plan. Your documents are encrypted from the moment you upload them.