Security & compliance

We don't own your data. We custody it.

Reep positions itself as a Digital Custodian, not an owner — every architectural and legal decision follows from that distinction.

Zero-knowledge architecture

We never see your data — not even by accident.

Encryption and decryption happen client-side. Reep's servers store ciphertext only. There is no master key, no support-staff override, and no backdoor — because the architecture doesn't include one.

what reep's servers see
7f3a9c1e2b8d4f6a0c5e1b9d3f7a2c8e
6b4d8f0a2c9e7b1d5f3a8c0e4b6d2f9a
— encrypted vault contents, indecipherable without your key —
RUFADAA & GDPR

Navigating the legal landscape of digital inheritance, by design.

RUFADAA-aligned

Reep's release framework is built around the Revised Uniform Fiduciary Access to Digital Assets Act, giving fiduciaries a clear, lawful path to act.

GDPR-native

Data minimization, the right to erasure, and explicit consent are built into the product, not bolted on for regional compliance.

Digital Custodian, not owner

Reep never claims ownership of stored data — a distinction that shapes everything from contract terms to deletion rights.

Data sovereignty & audit trails

You own it. We just keep it safe.

100% data ownership

Your data is portable and can be deleted at any time, no questions asked.

Jurisdictional compliance

Regional data centers comply with local privacy laws around digital inheritance.

Immutable audit trail

Every vault interaction is logged on a private, tamper-evident ledger to prevent fraud during transfer.

Questions for our compliance team?

Get in touch →