Security

Your private vault stays encrypted while DMS handles the workflow around it.

Encrypted Vault Contents

Your private materials stay protected.

  • Message bodies and secure notes
  • Titles and filenames
  • Uploaded documents and file contents
  • Private instructions prepared for release
Operational Metadata

DMS still needs a few details to operate.

  • Account email for OTP and reminders
  • Verifier and beneficiary routing details
  • Schedule settings and activity state
  • Billing and activation information
Important Limits

Good security language is honest about limits.

  • Email delivery can fail or be delayed
  • Verifiers can make mistakes
  • User setup choices matter
  • Losing a vault secret may make content unrecoverable
Locked Dashboard

The dashboard makes privacy visible.

If a dashboard casually shows plaintext filenames or note bodies, users will naturally assume the service operator can see them too. That is why DMS defaults to placeholders like “Encrypted file” and “Encrypted message” until the browser locally unlocks the vault.

Browser Decryption

What you open in the browser is not what the server stores.

The server stores encrypted vault materials while the user's browser handles the session-based reveal of filenames, messages, and files after a local unlock.

Admin Visibility

Admin sees workflow metadata, not your private vault.

Admin tools stop at status, counts, dates, reminder state, payment state, and release workflow visibility. No plaintext vault contents appear there.

Your Role

Strong privacy still depends on careful setup.

Users still need to choose trustworthy verifiers, keep recovery instructions safe, and test the full workflow before relying on it.

Plain-English Promise

DMS protects the vault while managing the process.

“We process the operational data needed to run reminders, verification, and release. We do not read the encrypted contents of your private vault in ordinary use.”

Encryption

Private vault contents and service data are treated differently.

DMS uses strong authenticated encryption for vault contents together with a clear separation between encrypted payloads and service metadata.

Trust

Privacy is strongest when it is understandable.

DMS explains what is encrypted, what is not, what the service depends on, and what risks remain, without pretending any system can guarantee every outcome.