Heirloom Life
Start your Will
Security & Trust

What we can tell you, accurately.

Estate documents are among the most sensitive records you can hold. We have written this page to describe what is actually in place today - not to match the length of a competitor’s security marketing page.

This page describes what is currently in place. Items not yet fully verified are noted as such. We will update this page as confirmations are in place rather than publish claims in advance.

Data encryption

Your data is stored on encrypted, access-controlled cloud infrastructure. Data is encrypted at rest and all connections are enforced over TLS. We do not store Will content in plaintext outside the secured database.

Authentication

Access to your account is managed through Supabase Auth, a purpose-built authentication service. New accounts use a magic-link email flow — no password is required to create your account. Returning users sign in with email and password. Session tokens are short-lived and signed.

Executor access controls

Executor access controls are on our build roadmap. Today, your Vault is accessible only to you with your account credentials. We will publish details of the executor access model before it is released.

Solicitor review independence

Every Will issued through Heirloom Life is subject to a standard solicitor quality review conducted by qualified Australian legal practitioners who are independent of Heirloom Life. For complex situations, an additional bespoke review can be requested through your Vault.

What we are not claiming

We do not hold ISO 27001 certification at this time. We are not claiming specific penetration testing results, specific uptime SLAs, or specific data residency guarantees until these are formally verified and documented. This page will be updated when those confirmations are in place. Where engineering has not yet confirmed specifics, we have noted them here rather than omitting the uncertainty.

Bank connections

How bank connections work

When you connect a bank or super account, you are redirected to a consent page operated by Basiq, a Consumer Data Right accredited data intermediary. Heirloom never sees your banking credentials. You authenticate directly on Basiq's hosted page - not through any Heirloom screen.

What data we request

We request account name, type and balance only, under the CDR scope bank:accounts.basic:read. We do not request transaction history. Your consent covers this scope specifically and can be revoked from your Vault at any time.

Basiq's role

Basiq is named on the consent screen alongside the CDR logo. This is a regulatory requirement under the Consumer Data Right framework and cannot be removed. You are consenting to Basiq collecting data on Heirloom's behalf under that framework. Basiq's privacy policy governs data in transit.

Questions about security?

If you have a specific security question that isn’t answered here, contact us directly. We’d rather acknowledge a gap than paper over it.

hello@heirloomlife.com.au