Trust

Security and trust are part of the product.

Tacitus holds an unusually sensitive mix of financial, health and family information. Clients hand over access to their lives, so trust is built into every layer: in the paperwork, in the permissions, and in what the client can check for themselves.

Stakes-based permissions

Each household sets its own limits in a signed permission charter. Anything irreversible, significant or health-related needs a person's approval.

Available now

No shared passwords

We use authorized-representative forms, delegate logins and view-only data connections. Every access is scoped, dated and revocable.

Available now

Unverified inputs are held

Anything that arrives outside a client's verified channels is quarantined until a person confirms it, so a fake bill can never trigger a payment.

Available now

Encrypted and separated

Client data is encrypted in transit and at rest, and each household is logically isolated. Staff see only the households they are assigned to.

Available now

A complete audit trail

Every action, by AI or by a person, is logged with who did it, why, and the evidence behind it. Clients can review it at any time.

Coming soon

The client owns the data

Clients can export everything, or have it deleted, whenever they choose. We never sell data or use it to train AI models.

Available now

Everything a client hands over is protected from the moment it arrives.

Passports, insurance cards, medical bills, tax records and, when unavoidable, account logins. Each item follows the same path: checked, classified, encrypted, shared only as much as the task requires, and logged every time anyone opens it.

  1. 1

    Checked on arrival

    Items are accepted only from the household's verified channels and scanned for malware. Anything from an unknown sender is quarantined until a household member confirms it.

    Available now
  2. 2

    Classified by sensitivity

    Every item is automatically assigned a tier: everyday, sensitive or restricted. The tier decides who can open it and how.

    Coming soon
  3. 3

    Encrypted per household

    Everything is encrypted in transit and at rest, with each household's data under its own encryption key. One household's data can never mix with another's.

    Coming soon
  4. 4

    Minimized for AI

    AI sees only what a task needs. ID numbers and account numbers are masked before processing, and our AI providers are contractually barred from keeping or training on client data.

    Coming soon
  5. 5

    Opened with a reason, then logged

    Only your assigned Chief of Staff can open restricted items, and only after stating why. Every access is logged, and the client is told when restricted items are used.

    Coming soon
Coming soonSample data · illustrative household

Reyes household vault

Your Chief of Staff's view. Try opening a restricted item.
Passport, Dana Reyes
RestrictedNo. ••••••4417
Social Security card, Dana Reyes
Restricted•••-••-6203
Metro Fiber account login
RestrictedPassword stored in secrets vault
Harbor Mutual auto policy
SensitivePolicy ••••2291
Riverside Medical EOB, Aug 22
SensitiveClaim ••••8830
Dishwasher warranty and receipt
EverydayExpires Mar 2, 2028

Logins are kept apart

Logins are stored only when an institution offers no delegate access. They sit in a separate secrets vault with separate keys, are never passed to AI models, and are never shown on screen. Your Chief of Staff uses them through a secure session without seeing the password.

Coming soon

Strong sign-in for everyone

Clients sign in with multi-factor authentication. Staff use hardware security keys on company-managed devices, and their access ends the moment their role changes.

Available now· ClientsComing soon· Staff

Paper handled with care

Physical documents are scanned on intake, then returned to the client or securely shredded, whichever the client chooses. Originals are never stored loose.

Available now

Emergency access is controlled

If a Chief of Staff is unavailable, emergency access to a household needs a manager's approval. It is time-limited, and the client is notified.

Coming soon

Backups are protected too

Backups are encrypted and kept separate from the live system. Deleting a client's data removes it from backups as they rotate out.

Available now

Least data, shortest time

We keep only what household operations require. When a document is replaced, the client chooses whether to archive or delete the old version.

Available now

Authority is granted in writing, scoped narrowly and always revocable.

Before Tacitus acts for anyone, the paperwork is in place. Every institution gets a specific, signed authorization that says what we can do and when it expires. The client decides, and the client can take it back.

The engagement agreement

Before any access is granted, the client signs a service agreement that defines Tacitus as an administrative agent. We coordinate, prepare and follow up. We don't give legal, medical or investment advice, and we never make decisions that belong to the client.

Available now
Client services agreementScope of services, confidentiality obligations, how data is handled and how the client can leave.
Signed at onboarding
Permission charterWhat Tacitus may do on its own, what needs approval and what it must never do. Covered in more detail below.
Signed at onboarding
Data handling consentWhat we collect, how it's stored and encrypted, who can see it, and a commitment never to sell it or use it for model training.
Signed at onboarding
Firm limit. Tacitus prepares, you sign. We never sign legal documents for you. A limited power of attorney is used only where explicitly appropriate and attorney-reviewed.

The permission charter: the client sets the rules.

Every household signs a permission charter at onboarding. It tells Tacitus which kinds of action it can take on its own, which need a quick approval, and which it must never take. Your Chief of Staff follows the charter, and you can change it any time by asking. Try adjusting it.

Some rules are locked for every household. No client can switch them off, and no one at Tacitus can override them.

Coming soonChanging your charter yourself, in the app, is coming soon.

Available nowSample data · illustrative household

Reyes household charter

Signed Sep 3, version 2
$100

Any action involving more than this amount needs your approval.

Book, move or cancel appointmentsDoctors, services, vendors already on file
Send documents to known providersOnly to institutions already on file
Cancel subscriptionsAfter flagging them as unused
Dispute a charge or billWith the supporting evidence attached
Pay bills to approved payeesIf you allow it, only within the dollar limit above
Share health information with familyFor example, a sibling helping with care
Move money between accountsTransfers, savings or investments
Locked for every household
Sign legal documents for youContracts, settlements, filings
Locked for every household
Change insurance coverageTacitus prepares options; you choose
Locked for every household
2 handled automatically, 5 need your approval, 2 never allowed. Actions over $100 always come to you first.
Available nowSample data · illustrative household

Authorization register

Every authorization on file, visible to the client. Tacitus tracks expiry dates and handles renewals.

6 active1 expiring in 30 days
InstitutionAuthorizationWhat it allowsExpiresStatus
Riverside MedicalHealthcare disclosure authorizationDiscuss billing and claims only; no clinical recordsAug 31, 2027Active
BrightCare DentalThird-party authorizationClaim status, resubmissions, billing questionsJan 15, 2027Active
Medicare (for Carol)Medicare authorization to discloseClaims, premiums and enrollment questionsOct 24, 2026Renewal sent
Harbor Mutual AutoAuthorized contactPolicy questions and quotes; no coverage changesDec 31, 2026Active
Metro FiberAuthorized account userBilling, plan changes within charter limitsNo expiry, reviewed yearlyActive
Checking and credit cardsRead-only data connectionView transactions; cannot move moneyReviewed yearlyActive
Crestview PropertiesThird-party authorizationLease questions and maintenance requestsDec 31, 2027Active

Revoking an authorization stops all Tacitus activity with that institution right away. The client receives written confirmation.

Trust the client can see and check for themselves.

A named person

Every household has a named Chief of Staff who has passed a background check and signed a confidentiality agreement. Clients always know who is working for them.

Available now

Access report in every digest

Each monthly digest lists every account Tacitus accessed, when and why. Anything unexpected stands out immediately.

Available now

Instant notices

Clients get an alert when an authorization is used for the first time, renewed or about to expire, and when anyone new is added to their household team.

Coming soon

A clean exit

If a client leaves, they receive a full export of their records. All access is revoked and their data is deleted within 30 days, with written confirmation.

Available now

Verification milestones

Independent assurance we are putting in place.

  • Professional liability insuranceErrors and omissions coverage for service work.On the roadmap· Before first retainer
  • Cyber liability insuranceCovers data incidents and client notification.On the roadmap· Before first retainer
  • Independent penetration testA third-party test of the platform and intake channels.On the roadmap· Before Phase 2 launch
  • SOC 2 Type II auditIndependent attestation of security controls.On the roadmap· Phase 2 target

Questions about how we handle your information?

Ask us anything before you decide. We would rather you know exactly how this works.

Get started