How Vault protects your data
Vault by FIRE Terminal is built with bank-level security at every layer.
Field-level encryption
Every sensitive field — account numbers, policy numbers, beneficiary names, phone numbers, and login credentials — is encrypted using bank-level encryption before being stored. Even in the event of a database breach, your sensitive data cannot be read without the encryption key.
Secure authentication
Authentication is handled by Clerk, a SOC 2 Type II certified identity provider. We support multi-factor authentication (MFA) and monitor for suspicious login activity.
Email identity verification
Vault Guardians and Legal Contacts must verify their identity via a 6-digit one-time code sent to their email address every time they access your Vault. Codes expire in 10 minutes and are verified server-side — no code is ever stored in plain text.
Sensitive data is always masked
Account numbers and policy numbers are never displayed in full. Vault shows only the last 4 digits (****1234). Login notes and EINs are never visible to Vault Guardians or Legal Contacts.
Complete audit trail
Every action in your Vault is logged — record additions, edits, deletions, and viewer access events. You can see exactly when your Vault Guardian last accessed your Vault.
Encrypted in transit
All data transmitted between your browser and Vault is encrypted using TLS. We enforce HTTPS on all connections.
To report a security vulnerability, contact [email protected]. We take all security reports seriously and respond within 48 hours.