Threat model

The things that could go wrong, and how each is answered.

A tool that decides when to reach your family should be judged on the failures it has thought about, not the features it advertises. Here are the three we consider fatal, the attacks we designed against, and how each is handled.

What this covers
Fatal failure modes3, NAMED
Threats mapped & answered18
Real incidents studied6
Written fromTHE CODE
Including the risks we have not yet closed
The three fatal failure modes

Everything else is in service of these.

Three ways a product like this can truly harm someone. The whole design exists to make each one hard.

Failure one

Breach

The most sensitive list a person will ever write, leaked.

Answered by: limiting account access and protecting the records, documents and personal information people choose to store. Rules that deny by default. No third-party trackers, no ads, no analytics beyond first-party counts.

Failure two

False trigger

The record handed over while the owner is alive and well.

Answered by: eighty quiet days, then a daily reminder for ten more, and one tap that cancels from any stage while the subscription is live. After a lapse the countdown carries on, so the answer is a different one: every message names two doors — subscribe again, or pause the countdown from your own device. What we accept, and say out loud, is that someone who cancels, ignores months of messages and never pauses will have their family contacted while they are well.

Failure three

Lockout

The living owner shut out of their own record.

Answered by: nobody is ever permanently locked out — except by losing the email itself, which we tell you at signup. Unlocking never needs the network; wrong PINs simply back off, and nothing is ever wiped.

The principle that decides ties

When unsure, we fail toward “you are alive.”

Wherever the mechanism cannot be certain, it delays rather than acts. A late handover is recoverable grief; a false one is not — it is fatal to the family, and to the product. Every close call is resolved the same way: assume the owner is well, and wait.

The corollary we hold ourselves to just as hard: a check that can never fire is not a cautious guard, it is an absence. So the guards are tested to prove they actually run — not merely that they exist.

Why the phone left identity

Your email is your account. Your phone number decides nothing.

A number is not trusted for anything in KinNest — not to log in, not to recover, not to release. That single decision retired a whole family of attacks at once.

What that closes
  • CLOSEDSIM swap and OTP interception — there is no number to hijack, because none is trusted.
  • CLOSEDThe recycled number. A telco reissues a dormant number and a stranger signs in as the owner — the nastiest one, because the very dormancy that starts the handover is what frees the number. Not applicable here.
  • CLOSEDRe-pointing identity to hijack the release. Identity cannot be re-pointed at all.
What it costs, said plainly
  • TRADEYour email carries more weight. Because identity rests on it, we tell you at signup to use an address you will keep — the one thing we cannot recover you from is losing the email itself.
  • TRADEIt is a deliberate trade of one rare, catastrophic failure for a class of common attacks. We think it is the right way round — but it is a trade, not a free win, and we say so.

Recovery, when you do control your email, is a ladder, never a gate: a nominee's confirmation on their own phone speeds it up, and its absence never blocks you. Every step alerts you with a one-tap cancel, and simply being locked out can never, by itself, get your family called.

The threat table, in plain words

Specific attacks, and what stops each.

A selection from the full table — chosen because each one shows how the posture actually behaves.

A nominee falsely reports the owner unreachable
The report door does not exist until the owner's check-in window has passed — day 91 on the three-month default, and it moves with a shorter window. Even then, seven more days of continued silence must pass, the owner is alerted the whole time, and one tap ends it from any stage.
Someone holds the owner's unlocked phone
On the phone, the app lock gates all content and every liveness action, and a notification tap is never accepted as proof of life — only a properly authenticated action is. That is not the whole answer, and we would rather say so: the same person can sign in on the web, where there is no app lock, so what stands between them and the record there is the account password and the second step. Closing it properly is on the list.
A wrong-address invitation
An invitation shows only the owner's name; nothing about the record is visible before release. One address maps to one person — a duplicate is refused.
A backend breach
Rules deny access by default. A breach could expose sensitive records and uploaded documents; not requesting account credentials does not remove that risk. Full end-to-end encryption is on the roadmap.
A malicious insider — us
Today the service is custodial, and we say so rather than claiming otherwise. The damage is minimised by holding directions rather than documents; the durable fix is end-to-end encryption, which we are building toward.
The record is never claimed — owner gone, nobody acts
A backup nominee wakes at day 121. Beyond that, one clock: the record is kept for three years from the last activity, warned two months ahead to the owner and every accepted nominee, then closed.
A subscription lapses and strands a family
It does not. The record goes into runoff: the clock keeps running, the family is still asked to check on the owner on the fixed date, and the handover still follows if they say they cannot reach them. What you pay for is the ability to keep postponing the handover, not the handover itself. The record is untouched either way.
Someone cancels the owner's subscription to stop the handover
One billing event covers several different facts — the owner cancelled, a relative cancelled, a card expired, or something happened to them — so we do not read it as a refusal. Cancelling therefore suppresses nothing. Stopping the countdown is a separate, deliberate act: signed in on the owner's own device, confirmed there, and never from a link in an email — because email access is exactly what this kind of attacker tends to have. The cost of that choice is accepted and disclosed rather than buried: an owner who cancels, ignores every message for months and never pauses will have their family contacted while they are perfectly well.
What others' failures taught us

The incidents we designed against.

Digital-legacy and password products have failed in public, expensive ways. Each one bought us a rule.

QuadrigaCX, 2019

The single keyholder.

A founder died as the only person who could open the vault; roughly $190 million became unrecoverable.

Our rule: a handover product must survive its maker. No flow is gated on one specific human, KinNest runs under a registered business with more than the founder able to act, and a named person can carry out the wind-down if the founder cannot. The trust that would hold the code and keys for the long term is a commitment we build toward as the product grows — not something we can point to today, and we would rather say that than imply it is already done — see continuity.

A memorialization prank

The false death report.

A fake obituary locked living users out of a major platform; getting back in took ID appeals and days.

Our rule: a report never restricts the living owner's access. Your word outranks it, always, for as long as you keep checking in.

DigiLocker, 2020

The side doors.

Flaws in signup and PIN reset — not login — let attackers validate as any user.

Our rule: sign-up, reset and recovery get the same scrutiny as the front door — the whole authentication surface, not just the login.

LastPass, 2022

Metadata is targeting data.

Vault backups were exfiltrated; unencrypted URLs and metadata let attackers choose which vaults to crack first.

Our rule: metadata and records can be sensitive, so access protection matters even when account credentials are kept elsewhere. And if we are ever breached, our disclosure posture is decided in advance: full and fast.

What is still on the roadmap

What is not in scope, said plainly.

End-to-end encryption. Today your record is encrypted in transit and at rest with AES-256, held under strict access rules. The next layer — where only the family you name can open the record, and we cannot — is being built. We will say it is done here on the day it is, and not before.

We do not defend against coercion of a living owner. There is no duress-PIN theatre we could actually back, so we do not pretend to. And we hand over information, never ownership — who inherits what is for your family and the law, never for us.

The fuller picture of how the machinery works: how KinNest is built →

Get early access See how it's built Free 30-day trial · No ads, and we never sell your data