Dedicated client environment
Each client deployment is designed as a separate application environment rather than a shared family-data workspace.
Security & Trust
AnyVault is designed for sensitive family-office records. This page summarizes the public trust model and links to the material used for deeper due diligence.
Public trust model
Each client deployment is designed as a separate application environment rather than a shared family-data workspace.
Client accounting, portfolio and document records are held in a client-specific database boundary.
Role-based access distinguishes owner, administrator, accountant, auditor and viewer responsibilities. Entity-scoped restrictions can further limit visibility.
TOTP two-factor authentication is enforced after enrollment in production, with failed-login lockout controls.
Production traffic is protected with HTTPS/TLS. The deployment model uses encrypted server storage and client-side encrypted off-site backups.
Transactions, source documents and journal entries remain linked so financial output can be reviewed back to its evidence.
AI autonomy is configurable. Low-confidence, blocked or consequential work can remain in a human review path before it becomes authoritative.
Owner-controlled MCP access can expose entity-scoped tools to supported AI clients with permissions and audit logging.
Self-operated deployments are designed without standing application-level access for AnyVault support personnel after implementation. Where Client Data access is needed for support, it is granted on a least-privilege basis for the required purpose and recorded in the audit trail. Assisted Operations personnel receive only the roles required for the agreed service.
The standard deployment model hosts live client data on dedicated infrastructure in the EU. Optional AI providers may process selected prompt or record content in the United States under Standard Contractual Clauses when those features are enabled.
AnyVault uses named infrastructure and service providers to operate the public site and client environments. The current subprocessor list and change process are published for review.
The privacy note explains public-form handling. The DPA and pre-engagement NDA provide the contractual starting point for deeper discussions.
Hosting, residency, backup, recovery and incident-response requirements are confirmed during implementation scoping because the final deployment model is client-specific.
AI providers are engaged only when AI features are enabled. A deployment requiring strictly EU-only processing can operate with AI disabled. Telegram notifications are enabled only at the client's request.
Contact dpo@anyvault.co for privacy, incident-response or data-processing questions. Product and architecture enquiries can be sent to support@anyvault.co.