The Only Step

Trust & Security

Security at Only Step

People trust us with a map to their financial lives. Protecting it is our core responsibility, and this page describes the safeguards in place today.

AES-128

Field-level encryption of financial institution names and notes

3 methods

Two-factor authentication: authenticator app, text message, or email

Read-only

Viewer and survivor access can never modify your records

No card data

Payments are handled by Stripe, not stored by Only Step

Data encryption

Your information is encrypted while it moves and, for the most sensitive fields, while it is stored.

  • Encryption in transitAll traffic between your browser and Only Step uses HTTPS with TLS. Connections to our PostgreSQL database use SSL.
  • Encryption at restFinancial institution names and notes are encrypted with AES-128 (Fernet) at the field level before they are written to the database.
  • Key managementEncryption keys are held as protected configuration secrets, separate from the database, and we maintain a documented key-rotation procedure.
  • PasswordsWe never store your password. We store only a salted, one-way bcrypt hash of it.
  • Uploaded documentsFiles such as death certificates are kept in private cloud object storage and are retrieved only through time-limited signed links.

Minimal by design

Only Step helps your family know where to turn. It is not built to hold the keys.

  • Locations, not credentialsWe record which institutions you use so your family knows who to contact. The service is designed so you never need to store the information required to access an account.
  • What we ask you not to enterOur forms do not ask for account numbers, passwords, PINs, or security answers, and we ask that you do not enter them in free-text notes.
  • Protected either wayAnything you do type into a note is encrypted at rest like other sensitive fields, but the strongest protection is not storing it at all.

Secure infrastructure

Only Step runs on established cloud platforms rather than self-managed servers.

RailwayApplication hosting and managed PostgreSQL database
CloudflareDNS management and private object storage (R2) for uploaded documents
StripePayment processing and subscription billing
ResendDelivery of account and security emails
TwilioDelivery of text-message verification codes
  • Environment separationProduction and staging run as separate environments with their own databases and file storage. Changes are tested in staging before release.
  • Browser protectionsThe site is served with a Content Security Policy and standard security headers.
  • Provider disclosureThe full list of service providers that process data on our behalf is in our Privacy Policy. Read the Privacy Policy.

Account protection

Layered sign-in controls protect your account even if a password is compromised.

  • Two-factor authenticationAvailable to every account through an authenticator app, text message, or email code, with one-time backup codes for recovery. Codes are required at sign-in once enabled.
  • Rate limitingSign-in and other authentication endpoints are rate limited to slow automated guessing.
  • Session managementAccess tokens are short-lived, refresh tokens rotate, and every token carries a unique identifier.
  • Password resetReset links use secure tokens tracked on the server. Sign-in and reset responses do not reveal whether an email address has an account.
  • Security alertsWe email you when your password or email address changes, so unexpected changes are noticed quickly.

Access controls

Only authorized people can reach your information, and every level of access is deliberately limited.

  • You decide who sees whatOnly the account owner can view and edit records. Owners invite Viewers and designate Survivors, and can revoke access at any time.
  • Read-only by designViewer and survivor sessions are technically restricted to read-only access and cannot change or delete anything.
  • Verified survivor accessBefore a survivor is granted access, they must submit a death certificate that is reviewed by our team. Survivor consent is recorded with a timestamp.
  • Staff access and audit trailEmployee access to user data is limited. Actions taken in the system are recorded in an append-only audit log, and any administrator impersonation is separately logged and shown with a persistent on-screen banner.

Payment security

Card data goes straight to a dedicated payment processor.

  • Handled by StripePayments are collected through Stripe’s embedded checkout. Card numbers are entered directly with Stripe, and Only Step does not store full payment card numbers.
  • Industry-certified processorStripe is certified as a PCI DSS Level 1 service provider, the highest level of payment card industry certification.
  • Verified payment eventsBilling events reach our systems through signed webhooks that are verified before they are accepted.

Email security

Account and security emails are sent through a dedicated email provider and are built to be recognizable.

  • Dedicated deliveryAccount emails, verification codes, and notices are sent through Resend from our own domain.
  • Bounce and complaint handlingAddresses that bounce or report complaints are automatically suppressed, which reduces the chance of account email reaching the wrong person.
  • Clear opt-outNewsletter emails include one-click unsubscribe.
  • What we will never askOnly Step will never ask you for your password or full financial account details by email.

Data retention & deletion

Records are handled carefully through their entire life, including deletion.

  • Soft deletionFinancial account entries are soft-deleted rather than removed immediately.
  • Controlled retention and erasureWhen an account is closed, personal data is held for a 90-day window, with two reminder notices to the address on file, and is then permanently erased by an automated job. A personal-data-free audit record of the erasure is kept.
  • Closed means closedA closed account cannot be reopened or billed, and its data is not restored after erasure.

Incident response

If something goes wrong, we investigate, contain it, and tell you.

  • InvestigationOur audit trail records actions taken in the system, which lets us reconstruct what happened during an investigation.
  • ContainmentWe can revoke sessions and rotate credentials and encryption keys as part of responding to an incident.
  • NotificationIn the event of a confirmed security incident involving personal information, we will investigate and provide notification as required by applicable law, with guidance on any steps you should take.

Continuous improvement

Security is maintained over time, not completed once.

  • Periodic reviewsWe conduct periodic internal security reviews of our access controls and safeguards.
  • Documented testingA written test plan covers access control, account closure, and data erasure workflows, and is run against our live environment.
  • Credential hygieneWe rotate secrets and keys when there is any reason to doubt their safety.

Report a security issue

If you believe you have found a vulnerability or have a security concern, please tell us. We review every report.

Submit a security report

Please begin your message with “Security Report” so we can route it to the right place.

Helpful to include

  • A description of the issue and where you found it
  • Steps to reproduce it
  • The potential impact, as you understand it

Please

  • Act in good faith and avoid accessing or changing other people’s data
  • Avoid disrupting the service or running automated attacks
  • Give us reasonable time to fix the issue before sharing it publicly

Last reviewed October 2026. This page describes safeguards in place at the time of review and is provided for information. Our binding commitments are set out in the Privacy Policy and Terms of Service. No method of transmission or storage is completely secure.