What protects your family’s information.
Last updated October 2026. Specifics, not slogans. Everything in the first list is how Heeron works today; the second list is what’s coming and when.
In place today
- Never the full numbers
- Heeron refuses to save a full account or card number, SIN, health card number or password. It blocks them as they’re typed and strips them from documents before anything is stored. Only the last 4 digits of an account are kept, so there is nothing to steal that could move money.
- Encrypted at rest, AES-256-GCM
- Every record (the family map, health details, documents, the activity log, two-step secrets) is encrypted with AES-256-GCM, the same standard banks and governments use. The last 4 digits are sealed separately and only revealed after you re-enter your 6-digit code, and each reveal is logged.
- Two-step sign-in for everyone
- Every account needs a password and a 6-digit code from an authenticator app. There is no way to turn it off. Passwords are hashed with scrypt and never stored in the clear.
- You decide who sees what
- Admins set each person’s access by area (Money, Legal, Health, Home & life) and by feature (invite, share, ask, upload, remove). Health and money start hidden. Someone planning for themselves can seal their plan until a waiting period passes.
- An activity log nobody can edit
- Who viewed, added, assigned or checked off what, and when, is written to an append-only log. Not even an admin can change or delete an entry. Everyone can see their own history; admins see the whole circle’s.
- Sessions that expire
- A session ends after 30 minutes idle. Share links for the hospital one-pager expire after 24 hours and can be revoked at any time. Sensitive actions (deleting, revealing last 4 digits) ask for your code again.
- Your data leaves when you do
- Download everything you can see as one file at any time. Leave a circle in one click. Admins can delete the whole circle, permanently, with their code.
- Nothing sold, nothing trained on
- No advertising, no data brokers, no third-party trackers on any page. If you turn on document reading with Claude, text is sent only after sensitive numbers are removed, and is not used to train models.
What we won’t store, on purpose
Full account, card, SIN or health card numbers. Passwords to other sites. Scans of government ID. Each one is a thing that can’t leak if it was never kept. For passwords, use a password manager and write in Heeron where the vault is.
Planned for the hosted version
- Hosted in CanadaPlanned
- The hosted version will run in Canadian data centres (Canada Central), with encrypted daily backups kept in Canada.
- PasskeysPlanned
- Phishing-resistant sign-in with Face ID, Touch ID or a security key, alongside the 6-digit code.
- Sign-in and access alertsPlanned
- An email when someone signs in from a new device or when anyone’s access level changes.
- Independent penetration testPlanned
- A third-party test of the hosted app before launch, with the summary letter available on request.
- SOC 2Planned
- Type I after launch, Type II a year later. Ask us for the current status.
If something goes wrong
Write to security@heeron.com. We read every report. If a breach ever affects your information, you’ll hear from us within 72 hours of us learning of it, with what happened and what to do.
Privacy
Heeron is built to the principles of PIPEDA, Canada’s federal privacy law: Collect the minimum, say why, let people see and correct what’s held, and delete it when asked. The privacy notice says exactly what is collected and why.