Skip to main content

Security details

The technical companion to our security overview, with every claim listed alongside the specific control behind it

Shield representing Orchard72 securityShield representing Orchard72 security

Will drafting is not available in United States flagUnited States yet

Available in:

  • Malta flagMalta
  • United Kingdom flagUnited Kingdom

Last reviewed: 22 Sept 2026

New here? Start with our security overview. Where a claim is gated on work in progress, we say so explicitly rather than implying coverage we don't yet have.

Security overview

Orchard72 applies layered controls across application, infrastructure, and operational surfaces. We follow widely-adopted industry practices, log security events for review, and update controls as the threat landscape changes.

The controls on this page apply across every feature on the platform: wills, asset registers, portfolio holdings, document vault uploads, identity verification, family and executor sharing, professional multi-client work, and corporate benefit programs. Where a control is audience-specific (joint-controller terms for professionals, employer-employee boundary for corporates) we say so explicitly.

Data encryption

Encryption in transit

All traffic between your device and our servers is encrypted using TLS 1.2 or higher.

Document envelope encryption

Files you upload to your document vault (identity documents, asset evidence, signed wills) are encrypted at rest with AES-256 server-side encryption on hardened object storage. On top of that, our envelope-encryption layer is active in every environment: each file is sealed with a per-document data key, wrapped under a per-account key, which is itself wrapped under a versioned master key held in our secrets-management service. A deleted document that passes the retention window has its per-document wrapped key and stored object destroyed together, so the file becomes mathematically unrecoverable, not just hidden. Closing your account triggers an immediate account-wide crypto-shred (the per-account key is destroyed, leaving every per-document key permanently unwrappable). The master key is versioned so it can be rotated without re-encrypting every record; older versions remain available on the read side during a managed transition window, then retired.

Field-level encryption for sensitive data

Identity-document and tax-reference numbers (passport, national identity and driving-license numbers, and tax identification and registration numbers) are encrypted at rest and paired with a one-way hashed lookup, so we can detect duplicates without decrypting the stored value. Visa numbers and residential address details (city, region and post code) are also encrypted at rest. These controls cover the fields listed here today; coverage expands as part of our ongoing security program.

Authentication and access control

Multi-factor authentication (MFA)

We strongly recommend enabling multi-factor authentication so your account requires two or more verification factors at sign-in.

Passkey authentication: The most phishing-resistant option, using your device's biometric or PIN unlock. Your biometric data never leaves your device; we only receive cryptographic proof of authentication.

Authenticator apps (TOTP): We support any standard authenticator app, including those built into many password managers. These generate time-based codes that change every 30 seconds.

SMS verification: One-time codes delivered to your registered mobile number. We recommend passkeys or authenticator apps where possible, because SMS is more vulnerable to interception.

Backup codes: When you enable MFA, we provide single-use backup codes for use if you lose access to your primary method. Store them securely offline.

Session management

We run a dual-timeout session model to balance security against usability:

  • Main session: Sliding window that extends with activity, up to a fixed maximum
  • Profile-edit session: Shorter window for sensitive changes, which you can extend only a limited number of times
  • Trusted devices: See the devices that have signed in to your account and remove any you no longer trust
  • Sign out everywhere: End every other session on your account at once
  • Draft saving: Long drafts save when you switch tab or close the page, so a lapsed session does not lose them

Device trust and login activity

We log access to your account so unusual patterns surface quickly:

  • Device fingerprinting: Identify and track recognized devices
  • Location signals: IP-derived location on each sign-in
  • Login history: Audit trail of sign-in attempts
  • Suspicious-activity alerts: Email, SMS or app notifications for unusual access patterns
  • Failed-login tracking: Rate-limits to deter brute-force attempts

Authentication data we store

For each registered passkey we store the WebAuthn public key, an encrypted credential identifier, sign counter, authenticator type, AAGUID, supported transport types, your user-friendly device label, and enrollment and last-used timestamps. The private key and the biometric or PIN unlock never leave your device. For device trust we store a fingerprint hash, IP-derived country/region/city, a 0 to 100 trust level, a progressive trust score that grows with use and decays over time, and counts of successful and failed sign-ins. For every authentication attempt we record the timestamp, outcome, multi-factor method, IP address, and device label, used for compromise detection and your own login-activity review. We process these data on the lawful basis of legitimate interests (UK GDPR Article 6(1)(f)). The full disclosure, including retention and your rights, is in Privacy Policy §1.1.

Password security

We enforce strong password requirements during account creation:

  • A minimum length, with numeric-only passwords and passwords too close to your personal details refused
  • Strength meter during creation
  • Self-service password reset with email verification
  • Block-list of commonly used passwords

Privacy and compliance

Data-protection law

We handle personal data in line with applicable data-protection law. The full legal framework is in our privacy policy.

  • Transparent processing: we describe what we collect and why
  • Access, correction, portability, and deletion rights
  • Data-minimization by default
  • Privacy-by-design across new features

Who at Orchard72 can see your data

Most of our team can't see your personal information at all. We split the work into roles, each with the smallest amount of access it needs to do its job. Whenever anyone opens your record, we record who looked, when, and why, and you can ask us for that record at any time.

  • Customer support. Sees your name, email, country, and which plan you're on, so we can answer your questions. They don't see your will, your assets, your documents, or your beneficiaries.
  • Billing operations. Handles refunds, subscription changes, and payment history. They see what support sees, plus your payment status. They don't see your personal card details (those live with our payment processor) or your will content.
  • Engineers. Look at error reports to fix bugs. The reports are sent without your account details attached, and sign-in credentials are stripped from them before they reach us. Engineers don't have access to your will, your account, or your documents.
  • Auditors. A small team that reviews who has accessed what, to make sure the rules above are being followed. They see the access log itself, never the underlying data.
  • Founders (one or two senior staff). Hold the highest level of access for genuine emergencies: a court order, a security incident, or a system fault that nobody else can fix. Their view is masked by default too: reaching an unmasked record takes a break-glass grant that is time-limited and tied to a stated reason, and every use is recorded. They don't browse your data day-to-day.

Three things sit underneath all of this:

  • Two-factor authentication is required for anyone on our team to reach the admin console.
  • Sensitive details are hidden by default even for the people who do have access: date of birth, ID numbers, phone numbers and addresses are masked. Revealing them creates a record.
  • Every action is logged in a record that nobody, including the person who took the action, can edit or delete: the database itself blocks both. Each type of record has its own retention period (for example twelve months for network details such as IP addresses, ten years for payment records), and records are removed only by our automated retention process once that period ends, never while a legal hold applies.

You can download your own account activity from your activity settings, and an evidence pack for each of your wills from its page in your account.

You can also ask us for the staff access record at any time. Write to our contact form and we'll send it on.

Operational security

Staff access

We constrain staff access to user data:

  • Background checks before hire
  • Least-privilege principle on production access
  • Confidentiality and acceptable-use agreements
  • Periodic security training

Monitoring

Operational monitoring covers the surfaces an attacker would touch first:

  • Application errors reported to a central error tracker, and infrastructure health alerts
  • Alerts on suspicious sign-ins, staff break-glass access and payment-processing failures
  • Defined incident-response runbook

Frequently asked questions

Ready to protect what matters?

Your draft is private, encrypted, and yours from the very first step

We use cookies to improve your experience. See our Cookie Policy (opens in a new tab) for details.