Encryption everywhere
All traffic is encrypted in transit with TLS, and all stored data is encrypted at rest. Sensitive vault values are additionally encrypted client-side before they leave your device, under keys scoped to your household.
Security
DynasticAI holds the documents families are most afraid to lose. We designed the platform around a strong-protection posture: each household operates as a closed universe, access is controlled and attributable, and every meaningful action is written down. This page is written for families, and for the security teams at institutions who review us.
Protection of data
All traffic is encrypted in transit with TLS, and all stored data is encrypted at rest. Sensitive vault values are additionally encrypted client-side before they leave your device, under keys scoped to your household.
Each household has its own envelope keys managed through AWS Key Management Service. Documents are wrapped per household, so one family's keys never open another family's vault.
Row-level security is enforced in the database itself, isolating every household's records at the data layer, not just in application code.
Control and accountability
Balances and sensitive values display masked until you choose to reveal them. Each reveal is a deliberate act, and each one is recorded in the audit ledger.
Every view, change, share, and reveal is appended to a ledger that cannot be silently edited, with a signed, court-ready export for when your family needs a defensible record.
Passkeys are the primary way in, with multi-factor authentication, idle-session locks, and a Quick Lock control. Access grants are role-based and can be time-bounded.
For institutional reviewers
We are building our controls and documentation toward a SOC 2 examination. We do not yet hold a SOC 2 report, and we will not claim one until it is complete. We are glad to share our current control posture under NDA.
Institutional deployments are designed with FERPA obligations in mind: minimal data collection, explicit data-ownership boundaries, and aggregate-only reporting to the institution. FERPA-aware describes our design posture; it is not a certification.
AI analysis runs through controlled server-side workflows via the Anthropic API under a zero-data-retention configuration. Household content is not retained by the model provider and is not used to train models.
Statement upload is the default and recommended way to bring accounts in, so no bank credentials are shared with us. Automatic bank linking is on the roadmap and will ship only when it meets this page's standard.
Security questionnaires, architecture reviews, and documentation requests: write to office@dynasticai.com. For how information is collected and used, read the Privacy Policy and Terms of Use.