Security & Compliance

    Built around encryption you control.

    Your vault is encrypted on your device with a passphrase only you hold. The notes below explain, in plain language, what we do, where your data lives, and how access works.

    Vault encrypted in your browser
    POPIA aligned
    FSP No. 55699

    Your vault is locked on your device

    When you set a vault passphrase, your browser uses it to encrypt everything you save - notes, account numbers, contacts, instructions - before it is uploaded. We do not store your passphrase on our servers.

    We receive and store the encrypted version. Without your passphrase, the contents cannot be decrypted. If you forget your passphrase, recovery is not possible on your behalf.

    How uploaded files are protected

    Documents you upload - wills, ID copies, policy schedules, title deeds - travel over an encrypted connection and are encrypted on our servers before they are written to storage. Each file gets its own random key, which we then lock with a master key our servers hold, so the storage provider only ever sees the locked version. Unlike the structured vault entries above, the encryption happens on our servers and not in your browser.

    Each file is checked when you download it again. If anything has been changed or swapped, the download is refused and the event is written to your audit log so you and we both see it.

    An audit log you can review

    Logins, vault unlocks, record changes, sharing, LifeKey requests and key-holder consents are all written to an audit log on your account. You can review it at any time and export it as a PDF pack for executors or attorneys.

    The log is append-only and chained at the database: every row carries the hash of the previous row, so any attempt to edit, delete or reorder entries is rejected and surfaces as an alert. The chain hash is included in the audit-log PDF export so executors and attorneys can verify the log offline.

    You can ask us to delete your account

    You can request deletion from your settings at any time. Your vault becomes inaccessible immediately, and your records and files are then removed from our active storage.

    Encrypted backups roll over on their normal schedule; the vault contents in those backups remain encrypted and age out with the rest of the backup.

    We keep a minimal record (account identifier, deletion timestamp, audit-log chain) for the period required by South African financial-services law, so we can answer regulatory queries. No vault contents are retained.

    Where your data lives, and your rights under POPIA

    When I Am Gone (Pty) Ltd is the responsible party for your personal information under POPIA. We process it lawfully and only for the purposes set out in our privacy policy.

    Vault data and uploaded files are held with our cloud and database providers under written POPIA processing terms. Third parties we use (e.g. email via Resend, card payments via Paystack) only see the operational data they need.

    You have the right to access, correct, delete or object to the processing of your personal information. Email our Information Officer at support@wheniamgone.co.za.

    If something goes wrong

    We monitor for unusual sign-ins, file-integrity failures and audit-log gaps. Security alerts go to a dedicated inbox that is checked during business hours with on-call escalation outside of them.

    If personal information is accessed by someone who should not see it, we will notify the Information Regulator and affected users in line with POPIA, no later than 72 hours after we become aware of the breach.

    Report a security issue

    Spotted something that looks wrong? Email our security team and we will respond within one business day.

    security@wheniamgone.co.za

    What we can and cannot do

    A plain summary of the boundaries built into the product.

    What we can do

    • Store your encrypted vault and files
    • Verify your email and identity
    • Run LifeKey access-request workflows
    • Provide you with a complete audit log
    • Notify you of suspected tampering
    • Honour POPIA data-subject requests

    What we cannot do

    • Read your encrypted vault contents
    • Recover or reset your passphrase
    • Decrypt files without your key
    • Override your sharing or access rules
    • Hand over readable data on subpoena
    • Rewrite history in your audit log

    Questions about security or compliance?

    We are happy to walk attorneys, advisers, partners and procurement teams through our controls in detail. Get in touch, or start a vault and inspect the controls yourself.

    Checking system status…

    Follow When I Am Gone

    More languages soon

    When I Am Gone (Pty) Ltd ("When I Am Gone") provides secure digital information storage tools only. When I Am Gone is not a law firm, financial adviser, or estate planning professional. This service does not constitute legal, tax, or financial advice. Consult qualified professionals for estate planning matters. Executors and beneficiaries are responsible for verifying information and obtaining professional advice before acting.

    Will documents created using When I Am Gone must be printed, reviewed, and signed in the presence of two competent witnesses as required by the Wills Act 7 of 1953. Electronic wills are not valid under South African law. When I Am Gone does not verify will validity, witness competency, or guarantee executor or Master of the High Court acceptance.

    When I Am Gone is the responsible party for processing your personal information in accordance with the Protection of Personal Information Act 4 of 2013 (POPIA) and the Promotion of Access to Information Act 2 of 2000 (PAIA). We process data based on your consent and contract performance. Data categories collected include identity, contact, estate, and financial information. Sensitive vault entries are encrypted in your browser before they reach our servers, and uploaded files are encrypted on our servers before they are stored; the security of your own device and passphrase remains your responsibility. Data is held with our cloud and database providers under written POPIA processing terms. Retention: active accounts indefinitely; deleted accounts for 7 years per legal requirements.

    You have the right to access, correct, delete, or object to processing of your personal information. Contact our Information Officer at support@wheniamgone.co.za for data subject requests. We will notify affected users of any data breach within 72 hours. See our Privacy Policy for full details.

    © 2026 When I Am Gone (Pty) Ltd. All rights reserved. Registered in South Africa.

    When I Am Gone is a registered Financial Services Provider | FSP No: 55699 | Regulated by the FSCA

    Certain services are financial services under FAIS. Administrative vault services are non-FAIS. | CPA cooling-off rights apply. | The FSP licence is held by When I Am Gone alone and is never re-presented under a partner brand.

    When I Am Gone logoWhen I Am Gone