Security

Last updated 27 September 2026

Your account

  • Two step sign in, always on. Every sign in needs your password and a six digit code we email to your address. Each code works once, for 10 minutes.
  • Passwords are never stored. We keep only a salted, slow hash of your password (PBKDF2 with 100,000 rounds), so it cannot be read back, even by us.
  • Limits on guessing. Repeated wrong passwords or codes are blocked for a while, and too many wrong codes ends the sign in.
  • Your email account matters. Sign in codes and password reset links both go to your email address, so keep that email account secure with a strong password of its own.

Your trust records

  • Only you. A trust record can be seen only by the person whose account it is in.
  • Where it is stored. Records and uploaded documents are stored with Cloudflare in its Oceania region, in Australia. See the privacy statement for details.
  • Encrypted connections. The whole site is served over HTTPS, and browsers are told never to connect without it.
  • Yours to take and to delete. You can download the whole trust record as one document at any time. Deleting your account deletes every trust you own and its documents.

Payments

Payments are handled by Stripe on its own secure pages. Your card details go to Stripe, never to us.

The free check and templates

  • The check keeps nothing. It runs in your browser. Close the page and your answers are gone.
  • The templates keep nothing. What you type stays in your browser until you print or save it.
  • Cookies only with your say so. Analytics cookies are set only if you accept them in the cookie banner. There are no advertising cookies, and your check answers are never recorded.

Found a problem?

If you think you have found a security problem, please email [email protected]. We will reply and fix it.