Built to protect the most private families in the world.
Soteria Collective handles confidential household and insurance information. This page explains, in plain terms, how that information is stored, processed, and protected — and which third parties (sub-processors) we rely on. We disclose every one.
How your information is handled
We never collect Social Security numbers or medical information.
- Inquiry stage. We collect only a name, email, and how you heard about us — never a document. Raw IP addresses are never stored; we keep only a one-way salted hash. Inquiries are automatically deleted after 30 days.
- Documents are never requested up front. Policy and household documents are only shared after a countersigned Mutual NDA and Letter of Authorization, through a single-use, time-limited secure link — never by reply email unless you choose to.
- Per-family vault. Documents are stored in an encrypted, per-household vault. Access is scoped server-side to a single family — cross-family access is impossible by design, not merely by policy.
- AI review (Iris). Our policy engine produces a draft review using agentic AI tools. Under commercial terms, your inputs are not used to train the provider’s models and are retained only for a limited safety-review period before deletion. We minimize identifying details sent for analysis, and every finding is reviewed and signed by a licensed practitioner before it reaches you.
- Human oversight. Every finding is reviewed and signed by a licensed practitioner before it ever reaches a member. Nothing is published to your dashboard automatically.
- Minimal-disclosure notifications. Internal alerts contain references and counts only — never your documents, financial figures, or personal details.
Sub-processors
We use only disclosed sub-processors with appropriate data-protection terms. We do not use undisclosed third parties for any part of the pipeline.
| Sub-processor | Purpose | Safeguards |
|---|---|---|
| Cloudflare, Inc. | Website hosting, document & inquiry storage, edge security, and bot protection. | Document & inquiry storage pinned to the European Union. TLS 1.3 in transit; AES-256 at rest. |
| Agentic AI analysis | AI-assisted policy analysis (the Iris engine). | Inputs are not used to train the provider’s models and are retained only for a limited safety-review period before deletion. We minimize identifying details sent for analysis, and all output passes through licensed human review before publication. |
| Resend | Transactional email (internal notifications). | EU sending region. Messages carry references and counts only — never client documents. |
Data residency, encryption & retention
- Residency. Member documents and inquiries are stored in the European Union.
- Encryption. TLS 1.3 in transit; AES-256 at rest.
- Retention. Inquiries auto-expire after 30 days. Vault documents are retained per your engagement agreement and destroyed on request or at the end of our engagement.
Questions
For any privacy or security question — including responsible-disclosure reports — contact seanc@soteriacollective.co.
This statement describes current practices and may be updated as our service evolves. It is provided for transparency and does not itself constitute a contract; specific obligations are governed by your engagement agreement.