Estate Architects LLC

Security

How we protect the Legacy Architects platform and the data you keep in your vault.

Last updated
July 30, 2026
Applies to
legacyarchitects.com
Questions
Contact us

This page describes our security measures for the software-as-a-service Legacy Architects platform on legacyarchitects.com (the “Site”), made available to you by Estate Architects LLC d/b/a Legacy Architects (collectively, “Legacy Architects,” “we,” “us,” or “our”).

01

Standards we follow

We are committed to following best practices outlined by OWASP, the AWS Well-Architected Framework, and SOC compliance standards, ensuring that our platform meets the highest security standards.

About this page

This page describes the security measures in place as of the date above. Security is an ongoing practice, and we may change or improve these measures over time; changes are effective when posted here. This page is provided for information and does not modify our Terms of Use or create any warranty or guarantee.

02

Authentication and access

Access to the platform is protected at several layers, from how you sign in to who on our side can reach production systems.

  • Secure authentication. We leverage Clerk to manage authentication, utilizing JWT with a Lambda Authorizer.
  • Multi-factor authentication (MFA). Users are required to verify their identity with a one-time passcode (OTP) sent via SMS.
  • Password security. We enforce industry-standard password policies: a minimum of 8 characters, rejection of compromised passwords at sign-up, and strong password enforcement requiring lowercase and uppercase letters, numbers, and special characters.
  • Email verification. Email verification codes are required for additional account protection.
  • Account lockout. Accounts are locked after 10 failed login attempts to prevent brute-force attacks.
  • Session management. Sessions are valid for a maximum of 24 hours, after which re-authentication is required.
  • IP blocklist and allowlist. We provide the ability to restrict access based on IP, ensuring secure connections.
  • Access control. Production access follows a least-privilege model, ensuring only authorized personnel can access critical systems.
03

Encryption

We encrypt your data both where it is stored and while it moves between systems.

Data at rest

Our database is a PostgreSQL RDS instance on AWS with AES-256 encryption for all personally identifiable information (PII). Encryption keys are periodically rotated to enhance security.

Data in transit

TLS 1.3 is used for securing communication between services, and data in transit is protected by TLS 1.2 or higher to provide end-to-end communication security.

04

Secure hosting

We use Amazon Web Services as our external security hosting provider. AWS meets System and Organization Controls (SOC) standards verified by independent third-party examination reports demonstrating how the provider achieves key compliance controls and objectives. For further details on AWS compliance, see aws.amazon.com/compliance/programs.

05

Your data belongs to you

You as the user own all data and file uploads in your account.

Who can access your data

  • If you’re working with an estate planning attorney, they can access your data for planning purposes.
  • If you invite collaborators to your vault, they can access your data based on the permission levels you grant.
  • If you seek tech support, credentialed members of the Legacy System team can access your data for troubleshooting purposes.

Privacy

We respect the privacy of our users and the need for appropriate safeguards and protection of the personal information that our users, employees, and contractors provide, including the data submitted using our products and services. Our Privacy Policy applies to the information we process, including that of users, customers, website visitors, trial users, and job applicants.

06

Backup, replication, and continuity

Data backup and replication

  • Database snapshots are taken daily to ensure data recovery capabilities. These daily backups are stored for 14 days.
  • All data stored on our AWS S3 is replicated from the US-East region to the US-West region, with versioning enabled on all buckets replicated to another region.

Business continuity and disaster recovery

We have a business continuity and disaster recovery plan that allows customers to continue to run our application in the unlikely event of an outage at AWS US-East.

07

Monitoring, response, and training

Monitoring and logging

We log data access to monitor for suspicious activity and ensure accountability. Any incidents are reviewed and all identified anomalies are investigated for a possible compromise.

Incident notification

Our goal is to notify users of an actual security incident within 24 hours of becoming aware of it.

Training

Our employees and contractors are provided with privacy and awareness training yearly and must pass a quiz each year. Developers train annually on secure coding guidelines, avoiding common coding vulnerabilities, and understanding how sensitive data is handled.

08

Contact us

If you have questions or concerns regarding this page, please contact us at:

Estate Architects LLC
d/b/a Legacy Architects

Address
304 S. Jones Blvd #1784
Las Vegas, NV 89107
Telephone
(702) 337-3860
Email
[email protected]