Encrypted in transit
Every request between the app and our servers travels over HTTPS (TLS). The app declares no non-exempt encryption beyond that standard transport.
Security
Heirloom holds the pictures people would be most upset to lose and least willing to see somewhere public. This page sets out the specific protections in place, in plain terms, and is deliberately free of claims we cannot back.
Each of these describes behaviour that exists in the app today.
Every request between the app and our servers travels over HTTPS (TLS). The app declares no non-exempt encryption beyond that standard transport.
Photos and videos are held in private object storage. The app receives short-lived signed links to the specific file it is about to show — there is no guessable public URL to a family’s photograph.
Account and vault passwords are stored only as one-way hashes. Nobody at Heirloom can read your password, and neither can anyone who obtained the database.
The Vault passcode is a separate credential from your account password. Compromising one does not open the other, and the Vault passcode is never accepted at sign-in.
Failed sign-ins and failed vault unlocks are counted and locked out independently. Someone guessing at your Vault cannot lock you out of your account, and vice versa.
Resetting or changing your password immediately invalidates every token issued before that moment, on every device — not at the next expiry, but at once.
Leaving the app relocks the Vault. Returning to it requires the passcode or your biometric again, so an unlocked phone is not an unlocked Vault.
Face ID, Touch ID and fingerprint unlock are handled by the operating system’s secure hardware. Heirloom receives a yes or no; it never receives your biometric data.
In a shared vault, removing an item requires more than one member to agree. Irreversible actions do not rest on a single tap by a single person.
Security pages are easy to overstate. These are the limits, stated plainly.
If you believe you have found a vulnerability in Heirloom, write to security@heirloom.setrick.com with enough detail to reproduce it. We will acknowledge your report, keep you updated while we investigate, and will not pursue legal action against researchers who act in good faith, avoid accessing other people’s data, and give us reasonable time to fix the issue before disclosing it.