Loading…
Loading…
FamilyVaults is the private operating system for a family’s financial life. Every asset, entity and debt in one place — and, beside each one, the reason it exists, in the words of the person who decided it.
One email when your place is ready. No sequence, no newsletter, no chasing.
Tool one · nothing is sent anywhere
Rough figures are enough. Everything below is computed in your browser and never leaves it — this page has no analytics and no form that captures these numbers.
Or start from a shape that’s close to yours:
Everything you own, before mortgages
ISAs, SIPPs, workplace schemes, general accounts
Your share, at whatever number you’d defend
Current accounts, savings, premium bonds
Mortgages, loans, cards — the total outstanding
Roughly what leaves the household each month
Household net worth
£1,618,000 held against £340,000 owed, across 4 records. Hover a band to break it apart.
The largest class is property, at 48% of assets. Spread enough that no single sale decides the household.
Cash covers well over a year of outgoings. Comfortable — worth asking whether some of it should be doing more.
21% borrowed against £1,618,000 of assets. Conventional — but only if every rate is actually recorded somewhere.
These are the three readings the app opens with. Not a score, not a grade — three sentences a household can act on, or decide not to.
Tool two · the part no bank does
Then watch the same record change as different people in your family read it. Access matures with responsibility — there is no separate children’s app.
Nothing written yet — the panel is showing an example.
Your partner sees exactly what you see, including the documents. Anything less and the person most likely to need this first is the one held furthest from it.
Tool three · the uncomfortable one
Tick what’s genuinely already written down and findable — not what you intend to do. The gaps are the honest answer, and they’re usually smaller than the dread.
The heaviest thing missing
Nobody has agreed to do the work.
A named executor who has actually said yes is the difference between a plan and a hope. It takes one conversation and one line in the record.
Where they’d hit a wall
Security · what we will and won’t claim
So the burden is ours to discharge, in specifics rather than badges. Where a protection isn’t built yet, this page says so — a security section that only lists strengths is telling you nothing.
A sealed item — a letter of wishes, a password list, a note meant to be read once — is encrypted in your browser with a one-time AES-256-GCM key, wrapped for each recipient with a key derived from their own passphrase at 600,000 PBKDF2 iterations. The passphrase never reaches us and neither does the content key. We store ciphertext and wrapped keys we have no way to unwrap, so this is a cryptographic claim rather than a permissions one: a total compromise of our database does not open a sealed item.
3 of these 8 are trade-offs or not yet done. A security section with nothing amber in it has not been written honestly.
The risk we can’t engineer away
The weakest point is you, on a bad day.
No encryption stops a household member being talked into forwarding a document, or a password being reused from a site that leaked in 2019. What we can do is make the consequences small and visible: every view is logged, every share is named and revocable, Legacy needs a second person, and nothing can be exported silently. Anything sealed needs a passphrase we do not hold, so it survives even someone signed in as you.
Who can reach your vault
Support access is opt-in per incident, expires on its own, and appears in your log like any other reader. We have never sold data and the terms forbid it outright.
FamilyVaults is a record-keeping tool. We never hold your banking credentials, never move money, and have no ability to transact on your behalf — so a breach of us cannot empty an account.
If we are breached · written before it happens
Every company writes this page after the incident, when the wording can be made to flatter them. Ours is here beforehand, which is the only version worth anything — and it commits us to specifics we could be held to.
What you would get from us
No holding statement, no waiting for the scope to be flattering, and no discovering it from the press.
What an attacker would actually hold
Sealed items are ciphertext plus wrapped keys we cannot unwrap. An attacker holding our entire database holds an unreadable blob and a PBKDF2 problem costing about a second per guess.
Two of these 5 are costs, not reassurances. A blast radius with nothing red in it has not been measured.
The business model · read it before you trust us
Any product free to the household is being paid for by someone else, and you are what they bought. Here is what every other route would have required us to do to you.
A household net-worth figure is among the most valuable targeting signals that exists — it prices every insurance, mortgage and investment pitch aimed at you. Serving ads would mean the product works better the more of your position we expose to buyers. There is no version of that we could run and still ask you to write down why you own things.
Why a promise isn’t enough
Every company that sold your data once promised it wouldn’t.
Promises survive exactly until the funding round that makes breaking them attractive. What holds is structure: a business that has no advertising product, no lead-generation arm and no data-sharing clause has nothing to switch on. If we ever wanted to, we would have to change the terms and tell you — and you would leave with a full export the same afternoon.
The commitments, in the terms
Not to advisers, insurers, lenders, data brokers, researchers or anyone else — identified, anonymised or aggregated.
No sponsored placements, no partner offers, no product recommendations in any surface of the app.
Nothing you write is used to train models, ours or anyone else’s. Wren reads your unsealed vault to answer you, cannot reach a sealed item at all, and retains nothing beyond your own log.
One file, complete and readable without us — not an API you have to hire someone to use.
Immediate from the live system, gone from backups within 30 days, with written confirmation when it is done.
This is the one we cannot fully guarantee — an acquirer inherits the terms, not our intentions. So the commitment is 90 days’ notice and an export before any change of control completes.
These are contractual, not aspirational. If any of them changes, the change is announced to every household 90 days before it takes effect, with a full export offered first.
◆ Founding families · 83 places left
We open in small groups so that every household gets set up properly rather than left with an empty vault. You’ll hear from a person.
One email when your place is ready. No sequence, no newsletter, no chasing.