Skip to content

Case study / 911 Vault

Sensitive documents released only when verified trustees prove the trigger

911 Vault is a collaborative security platform for life’s high-stakes documents: wills, financial records, medical directives, crypto keys and digital legacies that should only be released when a defined event happens. As lead freelance engineer I designed and built it end to end on React and Django, with event-triggered and time-release vaults, multi-party verification by trustees and zero-knowledge encryption. Nothing is released until verified trustees prove the trigger, and access before that event stays blind.

Client
911 Vault
My role
Lead freelance engineer — designed and built end to end
Sector
Security & digital legacy
911 Vault — product screenshot 1 of 2

The challenge

Some documents have to stay locked until the right moment, then reach the right people without fail. Storing a will, a medical directive or a set of crypto keys is easy. Controlling when they are released, and to whom, is not. If one person holds the only key, that person is a single point of failure. If release is too easy, the vault is not secure. If it is too hard, the documents never reach the people who need them.

The platform had to gate these documents behind a defined trigger and release them only when verified trustees prove it has happened. That makes this a security problem and a workflow problem at the same time. Encryption has to keep content private before the event, verification has to stop any one person acting alone, and every step has to leave a record.

  • Keep vault contents private before the trigger event
  • Require more than one trusted person to validate a release
  • Support time-based release as well as event-based release
  • Record activity on every vault in an audit trail
  • Give owners recovery paths that do not depend on a single channel

What I built

I was the lead freelance engineer on 911 Vault, working daily with the founder, and designed and built the platform end to end with a Django backend and a React front end. The work rested on the three areas the founder highlights in his recommendation: security, cryptography and database design.

Zero-knowledge encryption is the foundation. Vault contents are encrypted so the service stores them without being able to read them, which keeps pre-event access blind. No operator and no single trustee can open a vault early.

Release is controlled by the patent-pending Event Vaults and by time-release vaults. An Event Vault stays sealed until verified trustees prove a defined trigger, and multi-party validation means no single trustee can set off a release alone. Delayed-release buffers add a window between verification and release, so a mistaken or malicious trigger can be caught before anything is opened.

Around that core, granular audit trails record activity on each vault, dark-web monitoring watches for exposure of the owner’s data, and omnichannel recovery paths mean that losing access through one channel does not lock an owner out. Each of these removes a single point of failure.

Database design carried as much weight as the cryptography. Vaults, trustees, triggers, verifications and audit records have to relate to each other precisely, because the release logic is only as reliable as the data behind it. On top of that, the React front end delivers the guided workflow: registration, trustee selection, vault set-up and, when the time comes, controlled release.

Architecture and stack

Front end
React
Backend
Python · Django
Security
Zero-knowledge encryption · Multi-party validation · Granular audit trails · Dark-web monitoring
Release controls
Event Vaults (patent-pending) · Time-release vaults · Delayed-release buffers · Omnichannel recovery

Outcome

911 Vault gives people a way to store their most sensitive documents and decide in advance exactly how and when they are released. Contents stay private until the trigger is proven, release needs more than one verified trustee, and every step is recorded.

The design removes single points of failure on both sides. No one person can open a vault early, and no single lost credential or channel stops the right people getting access when the time comes.

Rod Ast, the founder, has said he plans to bring me back into the project once its proprietary aspects are settled. His full recommendation is below.

  • Pre-event access kept blind through zero-knowledge encryption
  • Multi-party validation before any release
  • Event-triggered and time-release vaults with delayed-release buffers
  • Audit trails, dark-web monitoring and multiple recovery paths
“His knowledge of security, cryptography, and database design was of crucial importance to our product’s successful development.”
Rod AstCEO & Founder, 911 Vault

Last updated 2026-10-03

Have a project like this?

Book a free 1-hour intro call, or send a short brief and I’ll reply with a proposed scope within two working days.