Estate planning software holds more sensitive data per client than almost any other category of legal tech. Not just names and addresses — net worth, account numbers, family conflict, health conditions, end-of-life wishes, and increasingly the credentials and private keys that control a client's digital life. A breach here is not an inconvenience. It is a confidentiality failure with your name on it.
Yet vendor diligence in this category is usually three questions long: are you encrypted, are you SOC 2, where's your privacy policy. All three have reassuring answers that mean very little on their own.
This is a longer list. Take it to any vendor you are evaluating, including us. Each question comes with what a substantive answer sounds like and what should make you press harder. You do not need to be technical to use it — you need to notice when an answer restates the question.
1. Where does our data physically live?
Ask for countries and regions, not "the cloud."
A good answer names the hosting region, states where backups live (often a different region, which is the part people forget), and says whether support staff access data from somewhere else.
Press harder if the answer is the name of a cloud provider. Every major provider operates in dozens of countries; naming one tells you nothing about which.
For Canadian firms specifically
This question is sharper north of the border, and it is worth separating three things that often get blurred together.
- Where the data is stored. Some Canadian firms treat Canadian residency as a hard requirement, whether because of provincial rules, institutional client demands, or their own risk position. Ask whether Canadian storage is available, whether backups stay in Canada, and whether it is the default or something you have to request at signup. Moving later is usually far harder than choosing correctly at the start.
- Who can reach it. Data stored in Canada but supported from an office elsewhere has left the country in every way that matters to a confidentiality analysis. Ask where support and engineering staff are, and what they can see.
- Which regimes apply. PIPEDA, Quebec's Law 25, and the Alberta and British Columbia provincial privacy acts carry different obligations, and a vendor operating in Canada should be able to speak to them without a scramble. Ask whether there is a named Privacy Officer you can actually contact, and whether cross-border processing is documented somewhere you can read.
Your own obligations here are yours to assess, and your law society may have views. What a vendor owes you is a clear factual answer you can take into that assessment.
2. What certification do you actually hold?
The phrasing matters enormously, and the distinctions are invisible unless you know to look.
SOC 2 Type 1 says controls were designed properly on one particular day. SOC 2 Type 2 says an auditor tested that those controls actually operated over a period, usually six to twelve months. "SOC 2 compliant," "SOC 2 aligned" and "SOC 2 ready" mean an audit has not happened.
A good answer is "Type 2, audited by a named firm, current report available under NDA." Better still is a live trust or security centre you can open yourself rather than a badge on a marketing page.
Press harder if the certification is years old with no renewal, or the word before "SOC 2" is doing a lot of work.
3. How is data encrypted, and who holds the keys?
Encryption in transit — TLS — is table stakes and tells you almost nothing. Every vendor has it. The real questions are about rest and granularity.
A good answer distinguishes full-disk encryption (protects against somebody stealing a drive, and little else) from field-level encryption of the sensitive values themselves. It says who can decrypt, and whether vendor staff can.
Press harder if you get "bank-level encryption" or "256-bit encryption" with no further detail. Those are marketing phrases, not architecture.
4. How do you handle credentials and private keys?
Specific to this category and frequently overlooked. A modern estate inventory captures things that are not merely sensitive but directly usable: account passwords, recovery phrases, crypto private keys. Storing those alongside ordinary form answers is a materially different risk.
A good answer describes separate handling — different storage, different access path, possibly split or distributed so no single system holds a usable secret — and explains how a fiduciary eventually retrieves them.
Press harder if the vendor treats a seed phrase as just another text field, or cannot explain the retrieval path at all. Capture without a retrieval plan is theatre.
5. Who at your company can see our client data?
Not "is it secure." Who, by name of role, and under what circumstances.
A good answer describes least-privilege access, says whether support staff can view client records or only account metadata, and confirms that any such access is logged.
Press harder if the answer is "only authorised personnel." That is a sentence, not a control.
6. How is access controlled inside our own firm?
Your likeliest exposure is not a sophisticated attacker. It is a departing paralegal, a shared login, or a junior with more visibility than they need.
A good answer covers distinct roles with real differences in what they can reach, the ability to restrict an individual client file, immediate revocation when somebody leaves, and permission checks enforced on the server rather than by hiding buttons.
Press harder if everyone at the firm sees everything, or if the only distinction is admin versus non-admin.
7. What authentication do you support?
A good answer includes phishing-resistant options — passkeys or hardware keys — not just SMS codes, and lets the firm require them rather than leaving it to each user.
Press harder if two-factor is optional, SMS-only, or unavailable for your clients as well as your staff. Your clients hold the same data you do.
8. Is there an audit trail, and what does it record?
This one does double duty: it is a security control and it is your evidence if anything is ever questioned.
A good answer records reads as well as writes, attributes every entry to a named person, includes failed and refused attempts, and cannot be edited or cleared from inside the product. Ask how far back it goes and whether you can export it.
Press harder if only changes are logged. A read matters — one export can take an entire client file out the door, and a blocked attempt is precisely what you would want to see afterwards.
9. What can your AI features see?
The newest question on this list and, in 2026, the one with the widest spread of answers. Nearly every vendor in the category has added AI. Very few can tell you crisply what it reaches.
Three things to separate:
- Scope. Can the AI read client data, or only configuration — your forms, templates and settings? These are different surfaces and they look identical in a demo.
- Enforcement. Is the limit architectural or instructional? "The model is told not to access client files" is a policy. "No operation exists that returns client data" is a boundary. Only one of those survives a clever prompt.
- Training. Is your data, or your clients' data, used to train anyone's model? Get this in writing, from the vendor and about their own AI subprocessor.
Press harder if the answer describes what the AI is instructed to do rather than what it is able to do.
10. Who are your subprocessors?
Every SaaS product is assembled from other services — hosting, email delivery, error monitoring, analytics, AI providers. Each one is a party your client data may touch.
A good answer is a published, maintained list you can read before signing, with a notification commitment when it changes.
Press harder if the vendor has to go and find out. It suggests nobody has mapped the data flows.
11. What happens to our data if we leave — or if you do?
Two scenarios, both worth asking about while everyone is friendly.
If you leave: can you export everything in a usable format, including documents and the full client record rather than a CSV of names? Can you do it yourself, at any time, or does it require a support request and a wait? How long is the data retained afterwards, and how is deletion confirmed?
If they fail: estate planning software holds records that need to outlive a vendor relationship by decades. Ask what happens to client access and data availability if the company is acquired or shuts down. There is no perfect answer, but there is a real difference between a vendor who has considered it and one hearing the question for the first time.
12. What is your breach notification commitment?
A good answer gives a defined timeframe in the contract, names who gets told, and describes what information comes with the notice. Ask whether they have ever had an incident and what changed afterwards — a candid answer to that is a better signal than a spotless record.
Press harder if notification is discretionary or undefined. You have your own notification obligations, and you cannot meet them on a timeline you do not control.
How Eternal Pro answers these
We would rather you ask us the same twelve questions than take a summary on faith, but here is where we stand.
Certification. SOC 2 Type 2, audited and certified by Oneleet, and actively maintained rather than a one-time exercise. You do not have to take our word for it or wait for a sales call — our security centre is open at trust.oneleet.com/eternal. We are also HIPAA-aligned, which matters here because estate intake collects health information: conditions, healthcare directives, end-of-life preferences. We treat that as protected regardless of whether HIPAA technically reaches us.
Canadian data residency. Eternal Pro is available to Wills, Trusts & Estates firms anywhere in Canada, and Canadian client information is stored only in Canada. Everything you or your clients enter lives and is backed up on servers in Quebec — storage and backup both, not storage in Canada with backups somewhere convenient.
There is one exception, and we would rather state it than let you discover it. When a client places credentials or keys into Cold Storage, that material is encrypted and split into pieces held in separate locations, some of which may sit outside Canada. No single piece is readable on its own, and nothing is reassembled unless the client asks for it. That is a deliberate trade: distribution is what makes the split meaningful, and confining every fragment to one country would weaken the protection it exists to provide.
On compliance, we handle personal information in accordance with PIPEDA and, where they apply, Quebec's Law 25 and the Alberta and British Columbia provincial privacy acts. Our Privacy Officer is reachable at privacy@eternal.me. Data location, cross-border processing, and how to make an access or correction request are all set out in our Canada-Specific Terms.
Canadian firms get the whole platform, not a reduced edition: branded automated intake, the Living Estate Dashboard for ongoing plan updates, full asset inventory, and integrations with Clio, 8am MyCase, Lawmatics and 9,000+ apps.
Encryption and credentials. TLS everywhere in transit, with sensitive fields encrypted rather than relying on disk-level encryption alone. Credentials and private keys are handled separately from ordinary intake answers, using the distributed cold storage described above, with a defined retrieval path for the people who will eventually need them.
Access. Distinct administrator roles, the ability to restrict an individual client file, and permission checks enforced server-side rather than in the browser. Passkey two-factor authentication is supported for firm staff and clients alike — your clients are holding the same information you are, so it would be strange to protect only one side of that.
Audit trail. Reads, changes and refused attempts, each attributed to a named person, and not clearable from inside the product.
Subprocessors. Listed in our Terms of Service, readable before you sign rather than on request.
Getting your data out. Every firm and every client can export all of their data, at any time, without asking us. No support ticket, no retrieval fee, no notice period. We think that is the right default for records that may need to outlive any software relationship, including ours — and a vendor confident in the product does not need to make leaving difficult.
AI. This is where we would most encourage a close look. Our Claude connector reaches configuration only — intake questions, templates, document styling, firm settings. No operation returns a client's answers, contacts, assets, documents, passwords, emergency card or vault. That is not a rule the model is asked to follow; the capability does not exist, so there is nothing to instruct. Stored credentials are excluded in both directions, and the one operation that resolves a client returns matter structure without so much as the client's name.
Anything above that you want evidenced rather than asserted, ask us. Reports are available under NDA, and the security centre is open to anyone.
Using this list well
Two habits make diligence worth the hour it takes.
First, ask the same questions of every vendor and write the answers down side by side. The differences are where the information is. Asked in isolation, every vendor sounds fine.
Second, notice how the answer arrives. A vendor who has genuinely done this work answers quickly, distinguishes between what they do and do not do, and volunteers a limitation without being cornered into it — the cold storage exception above is exactly the kind of thing worth listening for elsewhere. A vendor who has not done the work will restate the question back to you in more confident language. That signal is often more useful than the answer itself.