How your data is encrypted

    Different parts of your account use different encryption approaches, depending on who needs to access them and when.

    Structured vault entries

    Fields handled by the private encrypted vault are encrypted in your browser using your passphrase. Account records and metadata remain readable. Will preparation, contact management and practitioner services may process additional records in readable form. Check the Privacy Policy for the distinctions.

    Uploaded files

    Private uploads are encrypted in your browser. File names, categories and other metadata may remain readable. Choosing a supported sharing workflow can send the decrypted document to the server for scanning and conversion to server-controlled encryption. The service can decrypt that shared form to provide authorised access. The original owner-download workflow may no longer apply after conversion.

    Practitioner matter data

    Matter references, client details and legal notice workflow data entered through the practitioner portal are protected in transit and stored in encrypted form on our servers. Practitioner accounts are separately authenticated and authorised.

    Payment data

    Payment information is handled by Paystack. We do not receive or store your card details. We hold only a payment reference, subscription status and the last four digits of your card where Paystack provides them.

    What this means

    We cannot recover your private vault passphrase. Keep it and your account secure. That protection does not mean that all information processed by the service is unreadable to WIAG.

    Documents you share with a professional are re-encrypted on our servers so the professional can access them. For any shared document, the service can decrypt it to deliver it. Keep your passphrase and account secure.

    Access and audit trail

    Key account activity is recorded, including logins, vault access, changes, sharing, access requests and consent events.

    The audit log is designed to make tampering detectable.

    POPIA and data rights

    When I Am Gone (Pty) Ltd is the responsible party under POPIA.

    You may request access to your personal information, ask for corrections, object to processing, or request deletion where the law allows it.

    If something goes wrong

    We monitor for unusual access, file integrity issues and audit concerns.

    POPIA section 22 requires notification as soon as reasonably possible, subject to its specific exceptions and permitted delays. There is no general 72-hour waiting period. Where GDPR applies, its authority and data-subject notifications must be assessed separately.

    Important limits

    When I Am Gone is a registered Financial Services Provider (FSP No: 55699). It is not a law firm or estate planning professional.

    The vault and will tools are software tools only. They do not replace professional advice.

    Wills must still be printed, signed and witnessed in accordance with the Wills Act 7 of 1953 and strictly signed in accordance with your signing instructions.

    Independent assurance

    Last updated: 2026-05-09

    WIAG handles sensitive estate, identity and document data for South African families and the practitioners who serve them. The summary below is written for procurement, risk and information-security reviewers performing vendor due diligence on WIAG.

    Penetration testing

    WIAG commissions an external penetration test on an annual cadence, with a focused re-test after any major release that changes authentication, payments, file storage or the LifeKey death-trigger workflow. Findings are tracked to remediation in our internal task system; high or critical findings block the next release until fixed or a documented compensating control is in place.

    Most recent test window: April 2026 (annual external test). The next scheduled test window is April 2027.

    Compliance posture and roadmap

    Today

    • Registered Financial Services Provider (FSP No. 55699) regulated by the FSCA.
    • POPIA-aligned processing under a published Privacy Policy and Information Officer (Natalie Macdonald Spence, privacy@wheniamgone.co.za).
    • Internal controls baseline: documented threat model, STRIDE walkthrough, controls map, security requirements and risk register, refreshed on every security-relevant release.
    • PAIA manual published. Coordinated Vulnerability Disclosure policy published at /responsible-disclosure with safe-harbour wording and triage SLAs.

    Roadmap (targets, not current state)

    • Q4 2026Complete SOC 2 Type I readiness assessment and remediation backlog.
    • Q2 2027Achieve SOC 2 Type I attestation.
    • Q4 2027Begin SOC 2 Type II observation window.
    • Q2 2028Achieve SOC 2 Type II attestation; evaluate ISO 27001 certification path.

    Roadmap items are stated as targets, not as a current state. Where a target slips, this page is updated and the new quarter is published before the original deadline passes.

    Continuous monitoring, SAST and dependency scanning

    • Static application security testing (SAST)

      Runs on every change, plus a full scheduled sweep before each release.

      Triaged by the security owner; high/critical findings block release.

    • Dependency / supply-chain scanning

      Runs on every change against the lockfile and on a daily schedule against published advisories.

      Triaged by the security owner; CVEs with a working production exploit path are patched within 7 days.

    • Runtime application monitoring

      Always on. Tamper-alert windows, audit-chain integrity checks, suspicious access patterns and PDF queue health are monitored continuously.

      Pages on-call when an alert fires; weekly review of low-severity signals.

    • Threat-model refresh

      Re-walked on every security-relevant change (new external integration, new auth surface, new admin route, new file-upload flow, key rotation, security-advisory dependency upgrade, or launch milestone).

      Owned by the security owner; new ≥15-score risks are escalated to the WIAG owner before the change ships.

    Coordinated vulnerability disclosure

    Researchers can report security issues to security@wheniamgone.co.za under the published policy at /responsible-disclosure. We acknowledge reports within two business days, confirm severity and remediation timeline within ten business days, and credit the researcher in our hall of thanks once the issue is resolved (with their permission). Safe-harbour wording protects good-faith research conducted within scope. Read the full policy.

    Data-handling summary

    • Consumer vault entries (assets, debts, contacts, instructions) are encrypted in the user's browser using a key derived from their passphrase, before leaving the device.
    • Uploaded vault documents are encrypted in the user's browser; only ciphertext and an integrity hash are stored.
    • Authorised sharing workflows use server-side envelope encryption so professionals can be granted scoped, audited access without holding the consumer's passphrase.
    • Payment card data never touches WIAG infrastructure - it is handled by Paystack; we hold only references and last-four digits.
    • All state-changing operations write to an append-only audit log with hash-chained tip witnesses.

    Procurement contact

    For vendor questionnaires, security questionnaires (SIG / CAIQ), data-processing addenda, or to request the latest pen-test summary letter under NDA, contact security@wheniamgone.co.za with the subject line "Procurement". We aim to return completed questionnaires within ten business days.

    Download Security Overview (PDF)

    When I Am Gone is a life-file and estate-readiness platform. It is not a law firm, financial adviser, estate administrator, executor service, probate service or insurer. The platform stores information you supply and helps you keep it organised; it does not provide legal, tax or financial advice.

    When I Am Gone (Pty) Ltd ("When I Am Gone") is a registered Financial Services Provider (FSP No: 55699) providing secure digital information storage and estate-readiness tools. When I Am Gone is not a law firm or estate planning professional. For personalised legal, tax or estate planning advice, consult a qualified attorney or fiduciary practitioner. Executors and beneficiaries are responsible for verifying information and obtaining professional advice before acting.

    Will documents created using When I Am Gone must be printed, reviewed, and signed in the presence of two competent witnesses as required by the Wills Act 7 of 1953. Electronic wills are not valid under South African law. When I Am Gone does not verify will validity, witness competency, or guarantee executor or Master of the High Court acceptance.

    When I Am Gone (Pty) Ltd is responsible for its account and service administration. Private vault content uses browser encryption, while metadata and some requested services use readable or server-encrypted records. Our Privacy Policy explains purposes, providers, international transfers, retention and your rights. Account closure does not by itself confirm complete deletion. Lawfully retained records remain subject to appropriate access and use restrictions.

    You have the right to access, correct, delete, or object to processing of your personal information. Contact our Information Officer at support@wheniamgone.co.za for data subject requests. POPIA security-compromise notifications must be made as soon as reasonably possible, subject to the specific legal exceptions and permitted delays. See our Privacy Policy for full details.

    © 2026 When I Am Gone (Pty) Ltd. All rights reserved. Registered in South Africa.

    When I Am Gone is a registered Financial Services Provider | FSP No: 55699 | Regulated by the FSCA

    Administrative vault services are non-FAIS. Insurance services, where live, are financial services and are provided under the relevant authorisation, disclosures and product-provider terms. The will wizard and estate vault are software tools, not FAIS products. Insurance cover products are not yet on sale. When insurance products are offered, any remuneration will be regulated under FAIS and disclosed before any transaction. CPA and ECTA cooling-off rights apply where the transaction qualifies. The FSP licence is held by When I Am Gone alone and is never re-presented under a partner brand.

    When I Am Gone