Security at Heirvana

Last updated: May 10, 2026

At Heirvana, LLC, protecting your personal information and digital legacy is our highest priority. We've built our platform with security at its core — not as an afterthought. Below is a detailed overview of the technical and organizational measures we take to keep your data safe.

AES-256 Encryption

All data stored in your Heirvana vault is encrypted using AES-256, the same standard used by banks and the U.S. government to protect classified information.

TLS/SSL in Transit

Every connection between your device and our servers is protected by TLS 1.2+ encryption, ensuring your data is never exposed while traveling across the internet.

Zero-Knowledge Vault

Your sensitive vault contents are encrypted before they ever reach our servers. Heirvana employees cannot read your private notes, credentials, or document details.

Secure Cloud Infrastructure

Our platform is hosted on enterprise-grade cloud infrastructure with physical access controls, redundant systems, and 24/7 monitoring to ensure uptime and data integrity.

Multi-Factor Authentication

Add an extra layer of protection to your account with multi-factor authentication (MFA). Even if your password is compromised, your account stays secure.

Regular Security Audits

We conduct regular third-party security audits and vulnerability assessments to proactively identify and remediate potential risks before they can be exploited.

Data Encryption

All data stored within Heirvana — including your vault items, document form responses, beneficiary information, and account details — is encrypted at rest using AES-256 encryption. This is a military-grade standard that ensures even if storage media were somehow accessed, the data would be completely unreadable without the decryption keys.

Data in transit between your browser or mobile device and our servers is protected using Transport Layer Security (TLS 1.2 or higher). We enforce HTTPS across our entire platform and use HSTS (HTTP Strict Transport Security) to prevent downgrade attacks.

Account Security

Your Heirvana account is protected by several layers of security:

  • Passwords are never stored in plain text — they are hashed using industry-standard bcrypt algorithms
  • Multi-factor authentication (MFA) is available and strongly encouraged for all accounts
  • Automatic session expiration after periods of inactivity
  • Account activity notifications for new logins or suspicious activity
  • Rate limiting on login attempts to prevent brute-force attacks

Infrastructure Security

Heirvana's infrastructure is hosted on enterprise-grade cloud platforms with the following protections in place:

  • Data centers are SOC 2 Type II certified with physical access controls and surveillance
  • Network-level firewalls and intrusion detection systems monitor all traffic
  • Database access is restricted to authorized services only — no direct public access
  • All infrastructure changes go through a change management process with peer review
  • Automated backups are performed daily and stored in encrypted, geographically redundant locations

Access Controls

We implement strict role-based access controls (RBAC) internally. Heirvana employees only have access to the data necessary to perform their job functions. Access is granted on a least-privilege basis and reviewed regularly.

Sensitive customer data — particularly vault contents — is designed so that even Heirvana personnel cannot read the underlying information. Access logs are maintained for all administrative actions for accountability and audit purposes.

Secure Development Practices

Security is integrated throughout our software development lifecycle:

  • All code undergoes peer review before deployment
  • We follow OWASP secure coding guidelines to protect against common vulnerabilities (XSS, SQL injection, CSRF, etc.)
  • Dependency vulnerabilities are monitored and patched promptly
  • We perform regular internal and third-party penetration testing
  • A staging environment mirrors production, allowing thorough testing before any release

Third-Party Vendors

We carefully vet all third-party vendors and service providers that process or have access to your data. Key partners include:

  • Stripe — PCI-DSS Level 1 certified payment processing. Heirvana never stores your full credit card number.
  • Cloud Hosting Providers — Providers with SOC 2, ISO 27001, and FedRAMP certifications where applicable

All vendors are required to maintain appropriate security standards and are bound by data processing agreements.

Incident Response

In the event of a security incident or data breach, Heirvana has a formal incident response plan that includes:

  • Immediate containment and investigation of the incident
  • Notification to affected users without undue delay as required by applicable law
  • Coordination with law enforcement and regulatory authorities where required
  • A post-incident review to prevent recurrence

If you believe you have discovered a security vulnerability in our platform, please report it responsibly to support@heirvanna.com. We take all reports seriously and will respond promptly.

Your Role in Security

While we work hard to protect your data, security is a shared responsibility. We encourage you to:

  • Use a strong, unique password for your Heirvana account
  • Enable multi-factor authentication
  • Never share your account credentials with anyone
  • Log out of your account when using shared or public devices
  • Keep your email address and recovery information up to date
  • Report any suspicious account activity to us immediately

Our Security Commitments

AES-256 encryption at rest
TLS 1.2+ encryption in transit
Zero-knowledge vault design
Multi-factor authentication
Daily encrypted backups
Regular third-party audits
PCI-DSS compliant payments
OWASP secure development

Contact Us

If you have questions about our security practices or wish to report a vulnerability, please contact our security team:

Heirvana, LLC — Security Team

Email: support@heirvanna.com

Website: www.heirvana.com