Your digital legacy deserves enterprise-grade protection. We combine Google Cloud infrastructure, vault encryption, and a multi-step verification process to ensure your vault items are secure today and accessible to the right people tomorrow.


Vault data is encrypted in transit and at rest. MemoryShield holds the keys needed to complete trustee release after verification. That is how the life-check can work. This is not a zero-knowledge design.
Add an extra layer of security with SMS verification codes on every login.
Built on Google's enterprise-grade infrastructure with automatic security updates.
Configurable verification flow with backup contacts and optional legal review before release.
Payments handled by Paddle with PCI-compliant processing. We never see your card details.
We design the release process with U.S. fiduciary-access rules in mind, including RUFADAA. MemoryShield is not a fiduciary, and this is not a claim of legal compliance.
We use Google Firebase Authentication for all identity verification. Your password is never stored on our servers - instead, authentication tokens are signed with Google-managed keys and automatically rotated to prevent session hijacking. You can also sign in with Google OAuth for passwordless authentication.
Yes - SMS 2-Factor Authentication is available in your profile settings. Each login will require both your password and a one-time code sent to your phone. We're also working on hardware security key support (WebAuthn/FIDO2) for even stronger protection against SIM-swap attacks.
Yes. Data is encrypted in transit with TLS and at rest with AES-256 on Google Cloud. Extra encryption on individual vault items is optional. MemoryShield holds the keys needed for trustee release after verification, so this is not a design in which only you hold the keys.
Vault data is encrypted at rest, and MemoryShield holds the keys required to release it to your named trustees after a missed life-check and verification. That escrow is what makes automated release possible. This is not a zero-knowledge design. Authorized operators can access vault contents when the release protocol requires it. We do not claim that staff cannot read encrypted data.
We use Firebase Security Rules with a least-privilege model. Users can only access their own data at /users/{uid}/... paths. All other requests are denied by default. Admin access is strictly limited and audited.
We never touch your card numbers. All payments are processed by Paddle, a Merchant of Record. Webhook signatures are verified using HMAC keys stored in Google Secret Manager before any payment event is processed.
When you miss a Life Check, MemoryShield initiates a multi-step verification process: extended monitoring period, backup contact notification, optional legal document verification (death certificate), and a final waiting period. Only after all active steps complete are your vault items released to verified trustees.
Life Check is our automated wellness verification system. It sends periodic check-ins via email. If you don't respond within your configured deadline, MemoryShield begins the verification flow to ensure your digital assets reach your designated trustees when needed.
You name trustees and send them an invitation to accept that role. An invitation is not a cryptographic secret. Trustees cannot access vault items until a missed life-check has completed the verification flow.
We design the release process with U.S. fiduciary-access rules in mind, including the Revised Uniform Fiduciary Access to Digital Assets Act (RUFADAA). We keep audit logs of access events and support data export. MemoryShield is not a fiduciary, and this is not a claim of legal compliance.