Understanding Security

At Asfaly, we’ve built a password vault that truly protects your access in the event of death, without expecting you to be a security expert. Here’s how we do it, step by step.

Your data is unreadable to everyone (even to us)

AES-256-GCM Encryption

When you save a password in Asfaly, it’s encrypted before being stored. In practice, it’s turned into a string of unreadable characters.

  • We use the AES-256-GCM algorithm, an encryption standard considered highly robust, used by banks, militaries, and security-sensitive organizations.
  • Without the right key (your master password plus your authentication factors), no one can read your data — not even Asfaly.
  • Even if someone stole our servers, all they’d get is encrypted, unusable data.

In short: your passwords are turned into a “secret code” that only you can decrypt.

A password isn’t enough: two-factor authentication (2FA)

2FA is mandatory

A password can be guessed, stolen, or reused across multiple sites. That’s why Asfaly requires two-factor authentication (2FA) to access your vault. 2FA is like a door with two different locks:

  1. Something you know: your master password.
  2. Something you have: your phone, an authenticator app, or a security key.

To sign in, you need both:

  • You enter your password.
  • Then you confirm with a temporary code (generated by an app) or a notification on your phone.

What this means:

  • If someone steals your password, they can’t get in without your second factor.
  • If you lose your phone, you can still recover access using your backup codes (keep these somewhere safe).
  • It also protects your loved ones: with 2FA in place, they can’t access your accounts without your explicit consent.

Your data is stored in Switzerland — not just anywhere

Hosted in Switzerland

Where your data is stored matters a great deal for its protection. At Asfaly:

  • All your data is hosted on servers located in Switzerland.
  • Switzerland is recognized for:
    • strict data protection legislation,
    • strong political and legal stability,
    • protection against improper access by foreign jurisdictions.

In practice:

  • Your data isn’t scattered across data centers with unclear laws.
  • It’s subject to Swiss law and the Federal Act on Data Protection (FADP), which sets strict rules on who can access your information and under what circumstances.

We comply with the GDPR, Europe’s data protection rule

GDPR compliant

Asfaly is designed to comply with the GDPR (General Data Protection Regulation), the European regulation that protects your personal data. This means, among other things:

  • Transparency: you know what data we process and why.
  • Control: you can access, edit, export, or delete your data at any time.
  • Security: we implement technical and organizational measures to protect your information.
  • Respect for your rights: right of access, rectification, objection, erasure, and more.

In plain terms: you remain the owner of your data — we’re just a secure vault.

End-to-end encryption: not even Asfaly can read your data

End-to-end encryption means that:

  • Your data is encrypted right on your device (computer, phone).
  • It stays encrypted during transfer and on our servers.
  • Only your device, together with your authentication factors, can decrypt it.

What this means:

  • Not even we, at Asfaly, can read your passwords.
  • In the event of a legal request or a breach of our servers, the data remains unreadable.
  • You’re guaranteed that no one — except you (and your beneficiary, if you’ve designated one) — can access your accounts.

You stay in control of your digital life, even after you’re gone

Asfaly isn’t just for storing passwords. It also helps you organize what happens after you’re gone.

Transmission & control

  • Name a trusted beneficiary You choose someone who can manage your digital life in the event of your death.
  • Automatic transmission once your death is verified Once your death is officially confirmed (death certificate), your beneficiary can access the elements you’ve planned for them.
  • Have your digital life deleted after you’re gone You can decide that all or part of your digital life should be deleted.
  • Closing accounts (social media, email, health, retirement) Your beneficiary can close or manage your accounts according to your instructions.

All of this rests on:

  • strong encryption,
  • secure hosting in Switzerland,
  • and GDPR-compliant data processing.