Skip to content
Skip to main content
maivis

Security

Your family's data is encrypted before it leaves your device.

Files are encrypted on your device before upload. Your key is never exportable, not even by us. When AI does the work, it runs under contractual zero data retention. Nothing is stored by the AI provider. Nothing trains a model.

You control who inside your family sees which document, per document. maivis decrypts a file only to run maivis for you: when you open it, and when it is read to power document search, asset matching, and intelligence. Every decrypt is logged. Seal your vault in Settings and all decryption stops, including ours, until you unseal it.

What is in place today

Encrypted before it leaves your device

Documents are encrypted with AES-256-GCM on your device, then uploaded. The encrypted file is all that reaches our servers. If a storage bucket, database, or backup were ever stolen, what would be taken is ciphertext and a wrapped key, not readable documents. Decrypting them still needs a separate, authenticated Cloud KMS unwrap tied to your family's own key. A stolen backup cannot perform it.

Keys never leave Google Cloud KMS

Keys are generated and held inside Google Cloud KMS and are never exportable. A key cannot be copied out of Google Cloud, even by us. Each family gets its own dedicated key. A decryption key is used in memory only for the moment a document is read, never stored in plaintext. Every decrypt is written to an append-only access log. You can generate a Merkle root over your vault at any time to prove no document has been altered since.

Data stays in one place

Your financial data is stored on Google Cloud private infrastructure in one region, me-central1 (Doha, Qatar), for every family regardless of where you live. Backups and Cloud KMS keys sit in the same region. AI analysis runs on Gemini Enterprise Agent Platform under contractual Zero Data Retention. Your data is never stored by the AI provider, and never used to train models.

Your identity is stripped before every Gemini Enterprise Agent Platform call

Before any AI call, a privacy gateway removes names, emails, account numbers, passport numbers, and government IDs. The AI sees the wealth, not the family. "$2.3M in real estate across UAE and India", never "[family name], account 4521".

Passwordless sign-in

FIDO2 passkeys via WebAuthn. You sign in with your face or device PIN. There is no password to steal and no SMS code to intercept. The credential lives on your device and cannot be phished.

Isolation enforced on every query

Every family-scoped query is filtered by your family ID before it runs. The intelligence tables enforce that same boundary a second time inside Postgres with row-level security. Cross-family access is a blocking test on every deploy, not a code review convention.

Controls in production

AES-256-GCM client-side encryption
Cloud KMS key wrapping, one dedicated key per family, non-exportable key material
Append-only access log, with on-demand Merkle proof of document integrity
FIDO2 / WebAuthn passkeys, no passwords
TLS 1.3 in transit
DIFC Licensed CL5222
DIFC Data Protection Law 2020
GDPR aligned

How AI handles your data

maivis uses AI to generate wealth observations. Here is exactly what happens to your data, step by step.

Your identity is removed first

Names, emails, phone numbers, account numbers, passport numbers, and government IDs are stripped before anything reaches the AI. It cannot know who you are, because it is never told.

Only the numbers go

Values, holdings, spending, and the countries they sit in. That is what makes the analysis good. "$2.3M in real estate across UAE and India", never a name and an account number.

Nothing is kept

AI analysis runs under contractual Zero Data Retention on the Gemini Enterprise Agent Platform. Your data is not stored by the provider and is never used to train a model.

Every read is on the record

Each analysis is written to an append-only log with its scope. You can see what was looked at, and so can a regulator.

What we do not do

We never sell your family's data to third parties

We never store a vault document in readable form. Only ciphertext reaches storage.

We never share your family's data with advertisers

We never open your documents for anything other than running maivis for you, and every decrypt is logged

We never ask for your banking credentials. Only open banking tokens.

We never send your name, email, account numbers, or government IDs to AI providers

We never let AI providers store or train on your data

Questions about security?

Email us at legal@maiviswealth.com

IN WRITING

Everything above is in our contract

Every claim on this page is backed by a document you can read for yourself. Read them, share them, ask us anything.