Security
You're trusting us with some of the most sensitive information you have. Here's exactly what we do to protect it — described plainly, not oversold.
Encryption
Wills, insurance policies, and advance directives are encrypted at rest with AES-256, using a key managed in Azure Key Vault — never hardcoded, never checked into source control. Every connection to Dad Is Dead, and every file transfer, is protected in transit via HTTPS.
Authentication
Sign-in is handled by Microsoft Entra ID, the same enterprise identity platform used by Fortune 500 companies. We never see or store your password.
Infrastructure
Dad Is Dead runs on Microsoft Azure. Credentials for the external services we rely on (document storage, email, SMS) are stored in Azure Key Vault, and our application authenticates to Key Vault using a Managed Identity — not a stored username or password. Documents are stored with Cloudflare R2.
Access Control
Custodians you designate have no access to your vault while you're active. Access is granted only through our proof-of-life process, and you can reverse it at any time — even after a custodian has already been notified.
What we're still building
Dad Is Dead is hosted on Microsoft Azure, which provides automatic database backups as part of its managed infrastructure. We're actively working on a formal, tested business continuity plan with defined recovery targets, and we'll publish it here once it exists rather than describe it before it does.