Security & Trust

Privacy and control are part of the product.

AnyVault is designed for sensitive family-office records. This page summarizes the public trust model and links to the material used for deeper due diligence.

01Dedicated environment02Separate database03Role-based access04TOTP two-factor authentication05Encrypted off-site backups06Human-reviewed AI07Support access08Documented subprocessors
Private deployment exampleclient.anyvault.co

Public trust model

01

Dedicated client environment

Each client deployment is designed as a separate application environment rather than a shared family-data workspace.

02

Database separation

Client accounting, portfolio and document records are held in a client-specific database boundary.

03

Identity and permissions

Role-based access distinguishes owner, administrator, accountant, auditor and viewer responsibilities. Entity-scoped restrictions can further limit visibility.

04

Production authentication

TOTP two-factor authentication is enforced after enrollment in production, with failed-login lockout controls.

05

Transport, storage and backups

Production traffic is protected with HTTPS/TLS. The deployment model uses encrypted server storage and client-side encrypted off-site backups.

06

Traceable financial actions

Transactions, source documents and journal entries remain linked so financial output can be reviewed back to its evidence.

07

AI approval boundaries

AI autonomy is configurable. Low-confidence, blocked or consequential work can remain in a human review path before it becomes authoritative.

08

Controlled external access

Owner-controlled MCP access can expose entity-scoped tools to supported AI clients with permissions and audit logging.

09

Support access

Self-operated deployments are designed without standing application-level access for AnyVault support personnel after implementation. Where Client Data access is needed for support, it is granted on a least-privilege basis for the required purpose and recorded in the audit trail. Assisted Operations personnel receive only the roles required for the agreed service.

Data handling and diligence

The standard deployment model hosts live client data on dedicated infrastructure in the EU. Optional AI providers may process selected prompt or record content in the United States under Standard Contractual Clauses when those features are enabled.

AnyVault uses named infrastructure and service providers to operate the public site and client environments. The current subprocessor list and change process are published for review.

The privacy note explains public-form handling. The DPA and pre-engagement NDA provide the contractual starting point for deeper discussions.

Hosting, residency, backup, recovery and incident-response requirements are confirmed during implementation scoping because the final deployment model is client-specific.

Current client-environment subprocessors

AI providers are engaged only when AI features are enabled. A deployment requiring strictly EU-only processing can operate with AI disabled. Telegram notifications are enabled only at the client's request.

Hetzner Online GmbHDedicated server hostingEU · Germany / Finland
Backblaze Inc. (B2)Encrypted off-site backupsEU-Central bucket
OpenRouter, Inc.Optional AI gatewayUnited States · SCCs
Anthropic, PBCOptional AI model providerUnited States · SCCs
Voyage AI, Inc.Optional semantic retrievalUnited States · SCCs
Tavily, Inc.Optional AI-assisted web searchUnited States · SCCs
Telegram Messenger Inc.Optional outbound notificationsOutside EEA · SCCs

Security and privacy questions

Contact dpo@anyvault.co for privacy, incident-response or data-processing questions. Product and architecture enquiries can be sent to support@anyvault.co.

Book a private demo About the company