The things that could go wrong, and how each is answered.
A tool that decides when to reach your family should be judged on the failures it has thought about, not the features it advertises. Here are the three we consider fatal, the attacks we designed against, and how each is handled.
Everything else is in service of these.
Three ways a product like this can truly harm someone. The whole design exists to make each one hard.
Breach
The most sensitive list a person will ever write, leaked.
Answered by: limiting account access and protecting the records, documents and personal information people choose to store. Rules that deny by default. No third-party trackers, no ads, no analytics beyond first-party counts.
False trigger
The record handed over while the owner is alive and well.
Answered by: eighty quiet days, then a daily reminder for ten more, and one tap that cancels from any stage while the subscription is live. After a lapse the countdown carries on, so the answer is a different one: every message names two doors — subscribe again, or pause the countdown from your own device. What we accept, and say out loud, is that someone who cancels, ignores months of messages and never pauses will have their family contacted while they are well.
Lockout
The living owner shut out of their own record.
Answered by: nobody is ever permanently locked out — except by losing the email itself, which we tell you at signup. Unlocking never needs the network; wrong PINs simply back off, and nothing is ever wiped.
When unsure, we fail toward “you are alive.”
Wherever the mechanism cannot be certain, it delays rather than acts. A late handover is recoverable grief; a false one is not — it is fatal to the family, and to the product. Every close call is resolved the same way: assume the owner is well, and wait.
The corollary we hold ourselves to just as hard: a check that can never fire is not a cautious guard, it is an absence. So the guards are tested to prove they actually run — not merely that they exist.
Your email is your account. Your phone number decides nothing.
A number is not trusted for anything in KinNest — not to log in, not to recover, not to release. That single decision retired a whole family of attacks at once.
- CLOSEDSIM swap and OTP interception — there is no number to hijack, because none is trusted.
- CLOSEDThe recycled number. A telco reissues a dormant number and a stranger signs in as the owner — the nastiest one, because the very dormancy that starts the handover is what frees the number. Not applicable here.
- CLOSEDRe-pointing identity to hijack the release. Identity cannot be re-pointed at all.
- TRADEYour email carries more weight. Because identity rests on it, we tell you at signup to use an address you will keep — the one thing we cannot recover you from is losing the email itself.
- TRADEIt is a deliberate trade of one rare, catastrophic failure for a class of common attacks. We think it is the right way round — but it is a trade, not a free win, and we say so.
Recovery, when you do control your email, is a ladder, never a gate: a nominee's confirmation on their own phone speeds it up, and its absence never blocks you. Every step alerts you with a one-tap cancel, and simply being locked out can never, by itself, get your family called.
Specific attacks, and what stops each.
A selection from the full table — chosen because each one shows how the posture actually behaves.
The incidents we designed against.
Digital-legacy and password products have failed in public, expensive ways. Each one bought us a rule.
The single keyholder.
A founder died as the only person who could open the vault; roughly $190 million became unrecoverable.
Our rule: a handover product must survive its maker. No flow is gated on one specific human, KinNest runs under a registered business with more than the founder able to act, and a named person can carry out the wind-down if the founder cannot. The trust that would hold the code and keys for the long term is a commitment we build toward as the product grows — not something we can point to today, and we would rather say that than imply it is already done — see continuity.
The false death report.
A fake obituary locked living users out of a major platform; getting back in took ID appeals and days.
Our rule: a report never restricts the living owner's access. Your word outranks it, always, for as long as you keep checking in.
The side doors.
Flaws in signup and PIN reset — not login — let attackers validate as any user.
Our rule: sign-up, reset and recovery get the same scrutiny as the front door — the whole authentication surface, not just the login.
Metadata is targeting data.
Vault backups were exfiltrated; unencrypted URLs and metadata let attackers choose which vaults to crack first.
Our rule: metadata and records can be sensitive, so access protection matters even when account credentials are kept elsewhere. And if we are ever breached, our disclosure posture is decided in advance: full and fast.
What is not in scope, said plainly.
End-to-end encryption. Today your record is encrypted in transit and at rest with AES-256, held under strict access rules. The next layer — where only the family you name can open the record, and we cannot — is being built. We will say it is done here on the day it is, and not before.
We do not defend against coercion of a living owner. There is no duress-PIN theatre we could actually back, so we do not pretend to. And we hand over information, never ownership — who inherits what is for your family and the law, never for us.
The fuller picture of how the machinery works: how KinNest is built →