Trust
Security and trust are part of the product.
Tacitus holds an unusually sensitive mix of financial, health and family information. Clients hand over access to their lives, so trust is built into every layer: in the paperwork, in the permissions, and in what the client can check for themselves.
Stakes-based permissions
Each household sets its own limits in a signed permission charter. Anything irreversible, significant or health-related needs a person's approval.
No shared passwords
We use authorized-representative forms, delegate logins and view-only data connections. Every access is scoped, dated and revocable.
Unverified inputs are held
Anything that arrives outside a client's verified channels is quarantined until a person confirms it, so a fake bill can never trigger a payment.
Encrypted and separated
Client data is encrypted in transit and at rest, and each household is logically isolated. Staff see only the households they are assigned to.
A complete audit trail
Every action, by AI or by a person, is logged with who did it, why, and the evidence behind it. Clients can review it at any time.
The client owns the data
Clients can export everything, or have it deleted, whenever they choose. We never sell data or use it to train AI models.
Everything a client hands over is protected from the moment it arrives.
Passports, insurance cards, medical bills, tax records and, when unavoidable, account logins. Each item follows the same path: checked, classified, encrypted, shared only as much as the task requires, and logged every time anyone opens it.
- 1
Checked on arrival
Items are accepted only from the household's verified channels and scanned for malware. Anything from an unknown sender is quarantined until a household member confirms it.
Available now - 2
Classified by sensitivity
Every item is automatically assigned a tier: everyday, sensitive or restricted. The tier decides who can open it and how.
Coming soon - 3
Encrypted per household
Everything is encrypted in transit and at rest, with each household's data under its own encryption key. One household's data can never mix with another's.
Coming soon - 4
Minimized for AI
AI sees only what a task needs. ID numbers and account numbers are masked before processing, and our AI providers are contractually barred from keeping or training on client data.
Coming soon - 5
Opened with a reason, then logged
Only your assigned Chief of Staff can open restricted items, and only after stating why. Every access is logged, and the client is told when restricted items are used.
Coming soon
Reyes household vault
Your Chief of Staff's view. Try opening a restricted item.Logins are kept apart
Logins are stored only when an institution offers no delegate access. They sit in a separate secrets vault with separate keys, are never passed to AI models, and are never shown on screen. Your Chief of Staff uses them through a secure session without seeing the password.
Strong sign-in for everyone
Clients sign in with multi-factor authentication. Staff use hardware security keys on company-managed devices, and their access ends the moment their role changes.
Paper handled with care
Physical documents are scanned on intake, then returned to the client or securely shredded, whichever the client chooses. Originals are never stored loose.
Emergency access is controlled
If a Chief of Staff is unavailable, emergency access to a household needs a manager's approval. It is time-limited, and the client is notified.
Backups are protected too
Backups are encrypted and kept separate from the live system. Deleting a client's data removes it from backups as they rotate out.
Least data, shortest time
We keep only what household operations require. When a document is replaced, the client chooses whether to archive or delete the old version.
Authority is granted in writing, scoped narrowly and always revocable.
Before Tacitus acts for anyone, the paperwork is in place. Every institution gets a specific, signed authorization that says what we can do and when it expires. The client decides, and the client can take it back.
The engagement agreement
Before any access is granted, the client signs a service agreement that defines Tacitus as an administrative agent. We coordinate, prepare and follow up. We don't give legal, medical or investment advice, and we never make decisions that belong to the client.
The permission charter: the client sets the rules.
Every household signs a permission charter at onboarding. It tells Tacitus which kinds of action it can take on its own, which need a quick approval, and which it must never take. Your Chief of Staff follows the charter, and you can change it any time by asking. Try adjusting it.
Some rules are locked for every household. No client can switch them off, and no one at Tacitus can override them.
Coming soonChanging your charter yourself, in the app, is coming soon.
Reyes household charter
Signed Sep 3, version 2Any action involving more than this amount needs your approval.
Authorization register
Every authorization on file, visible to the client. Tacitus tracks expiry dates and handles renewals.
| Institution | Authorization | What it allows | Expires | Status | |
|---|---|---|---|---|---|
| Riverside Medical | Healthcare disclosure authorization | Discuss billing and claims only; no clinical records | Aug 31, 2027 | Active | |
| BrightCare Dental | Third-party authorization | Claim status, resubmissions, billing questions | Jan 15, 2027 | Active | |
| Medicare (for Carol) | Medicare authorization to disclose | Claims, premiums and enrollment questions | Oct 24, 2026 | Renewal sent | |
| Harbor Mutual Auto | Authorized contact | Policy questions and quotes; no coverage changes | Dec 31, 2026 | Active | |
| Metro Fiber | Authorized account user | Billing, plan changes within charter limits | No expiry, reviewed yearly | Active | |
| Checking and credit cards | Read-only data connection | View transactions; cannot move money | Reviewed yearly | Active | |
| Crestview Properties | Third-party authorization | Lease questions and maintenance requests | Dec 31, 2027 | Active |
Revoking an authorization stops all Tacitus activity with that institution right away. The client receives written confirmation.
Trust the client can see and check for themselves.
A named person
Every household has a named Chief of Staff who has passed a background check and signed a confidentiality agreement. Clients always know who is working for them.
Access report in every digest
Each monthly digest lists every account Tacitus accessed, when and why. Anything unexpected stands out immediately.
Instant notices
Clients get an alert when an authorization is used for the first time, renewed or about to expire, and when anyone new is added to their household team.
A clean exit
If a client leaves, they receive a full export of their records. All access is revoked and their data is deleted within 30 days, with written confirmation.
Verification milestones
Independent assurance we are putting in place.
- Professional liability insuranceErrors and omissions coverage for service work.On the roadmap· Before first retainer
- Cyber liability insuranceCovers data incidents and client notification.On the roadmap· Before first retainer
- Independent penetration testA third-party test of the platform and intake channels.On the roadmap· Before Phase 2 launch
- SOC 2 Type II auditIndependent attestation of security controls.On the roadmap· Phase 2 target
Questions about how we handle your information?
Ask us anything before you decide. We would rather you know exactly how this works.