Security & the vault
Everything your family is,
hosted in Switzerland.
Rebase holds the most complete picture of your family that exists anywhere. This page explains, plainly, how we make that safe.
UK company · Swiss data residency
The architecture
Five things that are
true by design.
Sealed where
it counts.
What you seal is encrypted on your device and stored as ciphertext. Vault keys stay with your household, so even we cannot read sealed items. Documents are read so Rebase can understand and file them, then encrypted on your device with AES-256-GCM. Passwords you enter are sealed immediately with envelope encryption: never stored in the clear, and never sent to the AI. A biometric passkey unlocks the vault; a Shamir 2-of-3 recovery kit covers lost devices.
UK company.
Swiss residency.
Rebase is a UK company. Your household data is hosted in Switzerland, kept apart from the desks and countries you file with. Cross-border families need a neutral place for the whole picture; Swiss data residency is that place on purpose.
The AI acts only
with consent.
Every AI action carries a risk class. Safe housekeeping runs quietly. Anything sensitive is proposed, shown with its reasoning and source, and waits in Review for your approval. Nothing is published without your OK.
Every access
has a name.
Access and changes are logged with who, what, and when. Security events are recorded, and the audit trail is yours to read, not a support ticket away.
Built to outlast
a bad day.
Lost phone, forgotten passkey, a family member who needs access in an emergency: the recovery kit and the household model are designed for those days. And your data is exportable, always.
Who can see what
Three parties. Three very different views.
Your household
Full access, your keys- Access is scoped per household, enforced by row-level security in the database itself
- Members see what their role allows
- Visibility controls let records stay private to one person
The system
Controls, not your vault keys- Vault-sealed values are ciphertext we cannot read
- Record metadata the product needs is protected by row-level security, TLS, and disk encryption
- Service roles are isolated from user data paths
The AI
Task-scoped, logged- The pipeline hands the AI the records relevant to its task, not your whole life
- Actions are risk-gated and wait for approval when sensitive
- Its access is logged like everyone else’s
Assurance
What is true today.
We publish what is true today, not what an auditor might say tomorrow. Questions about our security model, responsible disclosure, or anything above: write to security@rebase.one and we will answer.