Trust & Security
Last updated: July 2026 · Reviewed at least quarterly and immediately after any security event
Our public commitment to protecting your life's most important records.
TheJourneyOf.Life is built to safeguard the most important records of your life. This page is our public, plain-language commitment to security, data sovereignty, and continuity — no jargon, no fine print buried in a Terms of Service page.
Security Architecture
Every document, financial record, and message you store is encrypted at rest using AES-256-GCM — the same standard used by banks and governments to protect classified data. Every connection to our servers is encrypted in transit with TLS 1.3, so nothing you send us can be intercepted en route. Your Life Journal entries and Security Vault credentials use zero-knowledge encryption: they are encrypted on your device before they ever reach us, using a key derived from your password that we never see or store — meaning we could not read them even if compelled to. Time Capsule messages are encrypted at rest with a dedicated server-side key (distinct from any authentication key), since they must remain readable by a future recipient who has no pre-shared key with you. Multi-factor authentication (a one-time code emailed at every sign-in) is mandatory for every account, not optional, because a password alone is not enough to protect a life record.
Independent Audit Schedule
Penetration test: a third-party security firm engagement is being finalized for the quarter surrounding public launch — firm name, scope, and exact dates will be published here the moment the engagement is signed. SOC 2 Type I: audit engagement in progress. SOC 2 Type II: scheduled to follow Type I completion. If no audit has occurred yet by the time you read this, first independent audit will be published as: First independent audit: to be scheduled within 90 days of public launch. We would rather tell you exactly where we are than stay silent.
Bug Bounty Program
We welcome security researchers. Scope: helixa.life and all subdomains, our API, and our mobile web experience — excluding social engineering, physical attacks, and denial-of-service testing. Process: email security@helixa.life with a clear description and reproduction steps. We acknowledge every report within 2 business days, and will not pursue legal action against good-faith researchers who follow responsible disclosure. Reward tiers are being finalized ahead of launch and will be published here.
Audit Results
No independent audit has been completed yet — TheJourneyOf.Life is pre-launch. As soon as our first penetration test or SOC 2 assessment is completed, we will publish a summary of the results here, including any significant findings and exactly how they were resolved, within 30 days of completion. We believe a documented history of findings and fixes is more trustworthy than a page that only ever says everything is fine.
Uptime Commitment
We target 99.9% availability. Planned maintenance is announced in advance. Real-time and 90-day uptime statistics will be published on this page as our monitoring baseline matures.
Incident History
No security incidents to date. Should one ever occur, we commit to notifying affected users within 72 hours of confirming impact, publishing a holding statement here, and following a documented incident-response plan with a clear chain of notification.
The Data Sovereignty Charter
Adopted February 2026 — written into TheJourneyOf.Life's founding corporate documents, not our Terms of Service
- 1.Your data is yours. We will never sell it, rent it, or use it to train any model without your explicit, separate, revocable consent.
- 2.You may export a complete copy of everything you have stored with us at any time, in an open format, at no cost, with no waiting period and no support ticket required.
- 3.You may permanently delete your account and every piece of associated data at any time, with no retention beyond what law strictly requires.
- 4.Your Life Journal and Security Vault credentials are end-to-end encrypted — we cannot read them ourselves, even if a court or government compelled us to. Time Capsule messages are encrypted at rest with a dedicated key instead, since they must remain readable by a future recipient.
- 5.We will notify you within 72 hours of confirming any security incident that may have affected your data.
- 6.We will never share your data with law enforcement or any third party without a valid legal order, and we will notify you of any such request unless we are legally prohibited from doing so.
- 7.These commitments are written into TheJourneyOf.Life's founding corporate documents and survive any change of ownership, leadership, or business structure.
The seven commitments below are structural, not aspirational: they are binding on any future owner, investor, or acquirer of TheJourneyOf.Life, and cannot be unilaterally revoked. (Draft pending final legal counsel sign-off — this page will be updated with the finalized, counsel-reviewed text before public launch.)
What we can and cannot see
TheJourneyOf.Life Cannot Read (Zero-Knowledge)
- • Life Journal entries
- • Security Vault credentials
These are encrypted on your device before they ever reach us. Our servers hold only ciphertext. We do not have the decryption key — no engineer, no subpoena, no acquirer can read this content.
TheJourneyOf.Life Can Read (Encrypted at Rest)
- • Financial account data
- • Life Vault documents
- • Family Records
- • Contact information
- • Time Capsule messages
This data is encrypted on our servers and never sold or shared. Our AI uses it to provide personalized guidance — your Life Score, document categorization, insights. Time Capsule messages are encrypted at rest (with a dedicated key, separate from any authentication key) because they must remain readable by a future recipient who has no pre-shared key with you.
What happens if TheJourneyOf.Life ever stops operating?
Your Time Capsule messages are protected by a dedicated delivery obligation fund, a custodian arrangement, and a 100-year foundation mandate — independent of TheJourneyOf.Life's day-to-day business.
Have more questions?
Read our full FAQ for detailed answers on the Time Capsule delivery guarantee, our business model, and more — written for users, journalists, and partners alike.
Your data belongs to you
Export a complete copy of everything you've stored, or permanently delete your account and all of its data — anytime, no questions asked. It's yours.