Your information deserves serious protection.

Here’s how we approach it, including what we can’t promise.

This page describes the service as built. Last reviewed September 15, 2026.

WiseTomorrow holds some of the most personal information people have. We designed it around three ideas:

  1. You decide who can ask for your information, and what has to happen first.
  2. We protect it with layered safeguards.
  3. We’re honest about the limits.

Who we are

WiseTomorrow is built and operated by Dark Ecommerce Labs, LLC, a Florida company based in Sarasota. Our support and security addresses are read by the people who run the service, and we typically reply within one business day.

Your information is stored in the United States on Amazon Web Services. Stripe handles both payments and identity verification, and sees only what each of those jobs needs, as our Privacy Policy describes.

If we ever discontinue the service, you get at least 90 days’ notice and time to download your files and export your notes. Independent security testing is planned; we will publish a summary here when it is done rather than claim it before.

Who we are

How we protect what you store

Encryption in transit. Your connection to WiseTomorrow uses HTTPS. The connection between our application and our database is also encrypted.

Encryption at rest. Our database, servers and file storage — including the files you upload — are encrypted by our cloud provider, Amazon Web Services.

An extra layer for your most sensitive fields. Each Wise Box has its own encryption key. We use it (AES-256-GCM) to encrypt:

  • your notes
  • section names
  • file names and titles
  • your trusted people’s names and contact details

Each Wise Box key is itself protected by a master key in AWS Key Management Service, which keeps master keys in hardware security modules. The files themselves are protected by the encryption at rest described above, not by this extra layer.

What that means, plainly: WiseTomorrow is not end-to-end encrypted. Our servers decrypt your information so we can show it to you and, when your conditions are met, to the people you chose. We think that’s the right trade-off for a service meant to work when you can’t. It does mean we protect access to our own systems very carefully, as described below.

Where it lives. Data is stored in the United States on Amazon Web Services.

Backups. The database is backed up automatically, and those backups are kept for 7 days. Earlier versions of stored files are kept for a limited period. Backups help recover from mistakes and outages, but please keep your own copies of important originals.

Who can get into your account

Your account. You sign in with your verified email address and a password.

  • Passwords are stored only as salted, one-way hashes.
  • Changing your password signs you out everywhere else.
  • Sign-in attempts are rate-limited to slow down guessing.
  • Two-step verification is available in Settings — we strongly recommend it.

Sensitive changes need extra confirmation. We ask you to re-enter your password, and send you an email, when you add or change a trusted person, change your waiting period, or change your email address.

Our team. Our support tools don’t show the contents of your Wise Box. Production access is limited to a small number of authorized people, for operating, securing and repairing the service, and that access is logged.

How trusted people get access

This is the part that matters most, so here’s exactly how it works.

  1. 1

    They start from your Wise Card.

    Scanning it opens a request page. Having the card doesn’t unlock anything.

  2. 2

    We check they’re someone you named.

    The contact details they enter must match a trusted person you added and authorized, and they confirm their email address with a code we send. People you’ve just added, or whose contact details you just changed, can’t ask for 7 days.

  3. 3

    They verify their identity.

    Our identity-verification provider, Stripe, checks a government-issued ID and compares it with a live photo. The name on the verified ID must match the name you entered.

  4. 4

    We tell you.

    We email you about the request, and send a text message too if you’ve verified your mobile number. The message includes a way to stop the request, or to approve it early after signing in. We also tell your other trusted people, so any of them can raise a concern. If we can’t confirm that at least one notice to you was delivered, access doesn’t open automatically.

  5. 5

    Then we wait.

    The waiting period you choose — 72 hours, 7 days, 14 days or 30 days — gives you time to say no. Shorter periods of 24 or 48 hours are available only if you’ve turned on two-step verification and verified your mobile number. You can also add conditions for a person, such as supporting documents like a death certificate, a longer wait, or your own approval.

  6. 6

    If nobody says no, access opens.

    This happens whether or not you’re able to respond, which is what lets the people you trust help when you can’t. If you’re simply away, keep an eye on your email and texts.

  7. 7

    What they see.

    For each trusted person, you choose which sections they can receive — or everything — and whether they can download files. Use Preview to see what that looks like. Access lasts 12 months and can be renewed.

  8. 8

    Access is recorded.

    We keep a tamper-evident record of each request, the verification outcome, notices sent, your decisions, and what was viewed and downloaded.

You stay in control.

  • Stop a request any time before its waiting period ends. Pause or remove a trusted person, revoke access that was granted, or turn off a lost Wise Card whenever you need to. Removing or pausing someone also cancels any request they have in progress.
  • Revoking access stops future viewing. It can’t take back anything someone already saw or downloaded.

The limits of identity verification (please read)

Identity verification makes impersonation much harder. It can’t make it impossible. A determined criminal with a convincing forged ID, someone with the same name as your trusted person, or someone who has taken over their email or phone might get through.

That’s why WiseTomorrow uses several layers:

  • the card
  • the contact-detail match and email code
  • identity verification
  • notices to you and your other trusted people
  • the waiting period
  • our right to pause anything suspicious

We don’t decide legal questions. We don’t determine who inherits, who is a beneficiary, or who has legal authority. Being a trusted person gives nobody legal authority. If people disagree about who should receive your information, we put the request on hold rather than choose sides.

Monitoring and response

We rate-limit public pages and sign-in to slow down automated attacks.
Our systems send automated alerts when background processing fails.
We can place a security hold on an account if we see signs of compromise. This blocks sign-in and pauses activity, including access requests, until the situation is resolved.
If a security incident affects your personal information, we’ll notify you as the law requires.

Found a vulnerability? Please tell us at security@wisetomorrow.com. We welcome good-faith reports.

How you can protect your Wise Box

  • Turn on two-step verification. It’s in Settings. Your WiseTomorrow account controls who can receive your information, so it’s worth the extra step.

  • Protect your email account. It’s how we warn you about access requests. Use a strong password and two-step verification with your email provider.

  • Use a unique password. Don’t reuse a password from another site for WiseTomorrow.

  • Keep your email and mobile number current. Update them in Settings, verify your mobile number so we can text you, and check that messages from WiseTomorrow aren’t going to spam.

  • Enter your trusted people’s legal names. Use their names exactly as on their ID, plus contact details they actually control. Update them when life changes.

  • Keep your Wise Card somewhere safe. If it’s lost, turn it off in your account.

  • Choose a waiting period that fits your life. If you travel or are often hard to reach, a longer period gives you more time to respond.

  • Think before storing passwords. Many banks and online services don’t allow sharing logins, even with family. Look for their own legacy-contact options and note those instead.

  • Tell your trusted people about your plan. Then use Preview to see what they’d see.

Privacy commitments

  • We don’t sell your personal information, and we respect Do Not Track and Global Privacy Control.
  • We don’t use your stored content to train AI models.
  • We use your information to run WiseTomorrow, to follow your instructions, to prevent fraud, and to meet legal obligations. You can delete your account from Settings. Our Privacy Policy explains how long we keep information and what we delete.

Questions about security?

We’re happy to answer questions about how we protect your information.