Aftr asks you to trust it with things that matter. Your vault is encrypted on your device before it ever leaves. While you are alive, we cannot read it. Your family receives it only when a quorum of your chosen guardians confirms the time has come.
Every item you add to the Vault is encrypted using AES-256-GCM before it leaves your device. AES-256 is the same standard used by financial institutions and government agencies worldwide.
The “GCM” part stands for Galois/Counter Mode. It provides both confidentiality (no one can read the data) and integrity (any tampering is detected). If anyone were to intercept your encrypted vault, they would see only random bytes.
The encryption key is derived from your passphrase using PBKDF2, a key-strengthening algorithm. The key is computed on your device. Aftr never sees it.
Your encryption key is derived from your passphrase on your device. Aftr stores only the ciphertext: the locked box, not the key. While you are alive, we have no mechanism to read what you have stored. This is not a policy. It is how the system works.
This design has a consequence you should understand. If you forget your passphrase, your recovery phrase is the only way to restore access while you are alive. Aftr cannot reset it. Without your passphrase or recovery phrase, your vault cannot be accessed while you are alive. After your death, the guardian attestation process can release the vault to the people you chose.
There is also a deliberate difference from products that call themselves “zero-knowledge” with no qualification. Aftr is built to open for your family when you are gone. That is the whole point. After 3 of 5 of your chosen guardians independently confirm your death and a 72-hour dispute window closes, the vault can be reconstructed so your executor can do their job. Aftr does not initiate this. It takes your guardians. It takes the quorum. And it takes time.
You invite up to five Life Guardians: trusted people, typically a mix of family and friends. When the time comes, a quorum of three must agree before the vault is released.
This uses a technique called Shamir's Secret Sharing. Your vault access key is mathematically split into five shards. Any three shards can reconstruct it. Fewer than three cannot. Each shard is encrypted separately to that guardian's public key, so Aftr cannot read any shard.
The quorum requirement protects against two failure modes: a single guardian going rogue (one cannot act alone), and a single guardian becoming unavailable (you do not need all five).
The attestation process also requires a death certificate or coronial order. The quorum then votes. Only after the quorum is reached and the 72-hour dispute window closes does the vault open. At no point does Aftr initiate or override this process.
All Aftr data is stored in AWS ap-southeast-6, a New Zealand region. Your vault, your Life Story, your family tree: all of it stays in New Zealand.
We chose this deliberately. For a product that holds the sensitive records of families, offshore storage felt wrong. Your data is subject to New Zealand law, not the laws of a foreign jurisdiction.
Aftr Limited handles your personal information under a single privacy policy. If you are a California resident, it sets out your rights under the CCPA, including the right to know, to delete, and to opt out of any sale of personal information (we do not sell your data). A detailed description of how we handle your personal information is in our Privacy Policy.
Key points:
You can export everything in your vault at any time. If you cancel your membership, or if Aftr ever closes, you receive a full export window. Annual members receive at least one year's notice.
The vault export includes your encrypted data in a documented format. You are never locked in.