Security & Privacy

Your Family's Financial Map, Fort Knox Secure.

We built PRUMAA with one principle: your data is yours. Nominees see nothing until the trigger fires. We see nothing, ever.

Security Architecture

Six Layers of Protection

Your family's financial map is protected by multiple independent security layers — not just a password.

At Rest

AES-256 Encryption

All your asset data is encrypted at rest using AES-256 — the same standard used by banks and governments worldwide. Nobody can read your vault without your key.

Privacy First

Zero-Knowledge Architecture

We cannot see your data. Your vault is encrypted before it reaches our servers. Even our own engineers cannot access what you've stored.

Zero Credentials

No Passwords Stored. Ever.

We never ask for your banking passwords, insurance logins, or any credentials. Only asset locations and contact details — nothing that could be misused.

Locked Until Needed

Nominee Privacy

Your nominees see absolutely nothing until the emergency trigger fires. No previews, no notifications, no access. Your privacy is protected until the moment it matters.

Enterprise Grade

Supabase Infrastructure

Built on Supabase's enterprise-grade PostgreSQL with row-level security. Every row in the database is protected by policies that ensure only you can access your data.

DPDP Act 2023

DPDP Act Compliant

Fully aligned with India's Digital Personal Data Protection Act 2023. Your data rights are protected by law and by design — not just as a compliance checkbox.

How the Emergency Trigger Works

The trigger only fires after multiple failed check-ins and escalating reminders. It's designed to be safe, not hair-trigger.

  1. Monthly Ping Sent to You

    We send a simple message: "Are you okay?" via WhatsApp, SMS, or Email.

  2. No Response — Reminders Sent

    You don't respond within 48 hours. We send a second and third reminder over the next few days.

  3. Nominees Are Alerted

    After several days of no response, your nominees receive a message: "Please check on [Name]." They can confirm you're safe to reset the clock.

  4. Vault Unlocks for Nominees

    If nominees confirm an emergency, each nominee receives details of only the assets assigned to them — nothing more.

  5. Guardian Receives Everything

    If nominees are also unreachable, your Guardian receives the complete financial map — all assets, all nominees, and step-by-step claim instructions.

What Happens to My Data?

You are always in control.

Deletion

Delete your vault anytime from settings. All data is permanently erased within 30 days — no backups retained.

Export

Download a full export of your vault data at any time in JSON or PDF format.

Nominee Access

Nominees only ever see the assets assigned to them — never the full vault. Their access is one-time and read-only.

No Third Parties

We never sell, share, or use your data for any purpose other than protecting your family.

DPDP Act 2023 Compliance

India's Digital Personal Data Protection Act

PRUMAA is designed from the ground up to comply with India's Digital Personal Data Protection Act 2023. We treat your data rights as non-negotiable — not as a compliance checkbox.

Explicit consent before data collection
Clear purpose limitation for data use
Data minimization — only what's needed
Right to access your data anytime
Right to correction and erasure
Data breach notification within 72 hours
Grievance officer appointed
No cross-border data transfer without consent