Security & privacy

Built for
trust.

AllSet stores some of the most sensitive information you own. We take that seriously - every decision we've made, from where your data lives to how it's accessed, is designed to protect you and your family.

See how we protect you →
256-bit AES encryption
Every file and field encrypted at rest
EU data residency
Stored in Frankfurt, Germany. Never leaves the EU.
GDPR compliant
You own your data. We never sell or share it.
Zero-knowledge access model
Only you, and who you choose, can access your vault
Security & simplicity

Secure, but still simple to use when it matters.

Many systems are secure, but hard to access when needed. AllSet is designed to balance both strong protection for you, but simple access for your trusted person when the moment comes.

Strong protection for you
AES-256 encryption, EU data residency, and zero-knowledge access. Your vault is locked tight.
Simple access when needed
A printed key and a web address. Your trusted person needs no account, no app, no tech knowledge.
One person handing an envelope to another - a moment of trust and preparation

Your data is encrypted.
Full stop.

Every document you upload, every field you fill in — encrypted before it's stored. Not just in transit, but at rest. Even if someone gained access to our servers, your data would be unreadable without your credentials.

  • AES-256 encryption at rest
    The same standard used by banks and governments worldwide.
  • TLS 1.3 encryption in transit
    All data between your device and our servers is encrypted in transit.
  • Encrypted EU-based file storage
    Documents stored with server-side encryption in EU-region cloud storage.
Vault encryption status
Identity
Financial
Legal
Medical
Insurance
All items encrypted · AES-256
Last verified: just now
Zero plaintext storage
Data unreadable without your key

Three layers of protection

Security isn't one thing, it's a set of decisions made consistently, at every level of how AllSet is built.

Infrastructure security
AllSet is built on enterprise-grade infrastructure used by millions of businesses worldwide.
Hosted on enterprise-grade EU infrastructure with automatic security updates, continuous monitoring, and redundancy. The same class of providers trusted by banks and healthcare organisations.
Access control
Your vault is yours. Nobody at AllSet can view your documents. Access is cryptographically controlled.
Trusted contacts receive read-only access via a unique secret key. Keys can be revoked instantly. No employee, support agent, or third party can access your vault data.
Privacy by design
We collect only what we need to run AllSet. We never sell data, never use it for advertising, and never share it.
GDPR compliant · EU data residency · You can delete your account and all data at any time, permanently.

Your data never
leaves Europe.

Every piece of data AllSet stores, your documents, vault entries, account details, is held on servers located in the EU. Specifically Frankfurt, Germany.

This isn't just a compliance checkbox. It's a deliberate choice to make sure your data is subject to the strongest privacy protections in the world.

  • Database — EU Frankfurt
    Your vault structure, account info, and metadata stored in an enterprise-grade, EU-hosted database.
  • File storage — EU region
    Uploaded documents held in encrypted EU-based cloud storage with server-side encryption enabled.
  • Email - transactional only
    We only email you when necessary to run your account. No marketing without your explicit permission.
EU data centre
Physical access key

You decide who
sees what. Always.

AllSet's access model is built on the principle that you, and only you, control your vault. Trusted contacts can only access what you explicitly allow.

Cryptographic secret keys
Each trusted contact gets a unique key. Keys are cryptographically generated and impossible to guess.
Read-only access
Trusted contacts can view your vault but can never edit, delete, or download anything.
Instant revocation
Generate a new key at any time. The old key is immediately invalidated. No exceptions.
Per-category permissions (Advanced)
Choose exactly which vault categories each trusted contact can see.
GDPR Compliant
Full compliance with EU data protection regulation
EU Data Residency
All data stored in Frankfurt, Germany
AES-256 Encrypted
Bank-grade encryption at rest and in transit
Right to Delete
Delete your account and all data permanently, any time
Security questions

Frequently asked

Honest answers to the questions people ask most.

Can AllSet employees see my documents?
+
No. Your vault data is encrypted and access-controlled so that only you, and trusted contacts you've authorised, can view it. No AllSet employee or support agent has the ability to read your documents.
What happens to my data if I cancel?
+
AllSet's Essential plan is a true lifetime purchase, no subscription, no renewals. The Complete plan is $89/year to keep extended features active. Your vault and data are never affected.
What if someone finds my trusted contact's printed key?
+
Anyone with the physical key can access your vault in read-only mode. This is by design and it's meant to be simple for your trusted person. If a key is ever lost or compromised, you can generate a new one instantly from your account, which immediately invalidates the old one.
Is AllSet GDPR compliant?
+
Yes. AllSet is an EU-registered company, stores all data in the EU (Frankfurt, Germany), and is built in full compliance with GDPR. You have the right to access, correct, export, and delete your data at any time.
Do you sell or share my data?
+
Never. AllSet does not sell, rent, or share your personal data with any third party for marketing or commercial purposes. The only data shared with third parties is what's strictly necessary to operate the service (e.g. cloud storage providers), and all such providers are contractually bound to GDPR standards.
What if AllSet shuts down?
+
Advanced plan users can export their full vault as a PDF at any time, keeping a local copy completely independent of AllSet. We'd also provide notice and an export period before any service discontinuation.
Emma, Founder of AllSet

Security isn't a feature.
It's the foundation.

AllSet exists because losing a loved one is hard enough. The last thing anyone should face is months of searching for documents, accounts, and contacts, on top of grief.

Every security decision we've made comes from that same place. We're not a big tech company. We're a small team that built something we wish had existed. And we treat your data the way we'd want our own treated.

— Emma, Founder of AllSet

Ready when you are

Your vault is waiting.
Secure from day one.

Start with a few items. Build over time. Everything you add is encrypted, protected, and ready, exactly when your family needs it.