All insights

Sovereignty, Data & AI

Where Should a Family's Data Actually Live?

A family's data should live in one owned, secure, family-controlled single source of truth — not scattered across advisors' systems. Why location determines control.

Published 4 min read Essay

Overview

A family's data should live in one owned, secure, family-controlled place — a single source of truth the family holds, rather than scattered across advisors' systems. Where the data lives determines who controls it, who can see it, and whether it survives a change of provider. The right answer prioritises ownership and control over convenience.

Most families have never decided where their data lives. It ended up dispersed by default, a copy in each provider's system, with no one holding the whole. That default is the problem worth fixing.

Where does a family's data live today?

Today, a typical family's data lives everywhere and nowhere. The bank holds the portfolio, the accountant holds the tax picture, the lawyer holds the entities, and various portals each hold a slice. The consolidated whole exists only when someone assembles it by hand, and often only inside the founder's head.

This dispersal is not the result of a decision. It accumulated, one provider at a time, until the family's most important record had no home. The consequence is that no one — not even the family — can see the full picture without effort, and no one truly controls it.

Most families never chose where their data lives. It scattered by default.

Where should it live?

A family's data should live in one place the family owns and controls: a single source of truth that consolidates every entity, asset, advisor, and obligation, held on infrastructure the family governs rather than a provider's. Advisors and tools connect to it; they do not hold it.

The principle is a home, not a hosting choice. The data has one authoritative location, owned by the family, from which everything else is fed. Where that home physically sits — cloud or otherwise — is a secondary question addressed in on-premise vs cloud. What matters first is that the home exists and the family owns it.

What does "owned and controlled" actually require?

Owned and controlled requires three things: ownership of the record itself, control over who can access it, and security appropriate to what it holds. Ownership means the master copy is the family's, not a vendor's. Access control means the family decides who sees what. Security means the record is protected at a level that matches its sensitivity — because a family's consolidated picture is among the most sensitive records it holds.

These are governance choices as much as technical ones. The strongest security in the world does not deliver control if the family does not own the data it protects. Ownership and control come first; the security serves them.

Why does location determine control?

Location determines control because whoever holds the data sets the terms for it. Data in a provider's system lives under that provider's rules — their access, their retention, their pricing, their continuity. Data in a family-owned home lives under the family's rules. Where the record sits decides who holds the keys.

This is the build-versus-rent question applied to the core record. Renting the periphery is fine. Renting the location of the family's master picture means renting control over it — and control is the thing that matters when a provider changes, raises fees, or exits.

How do you consolidate without losing security?

You consolidate securely by bringing the picture into one owned home built for the purpose, rather than emailing spreadsheets between advisors. Consolidation and security are not in tension when done properly; the scattered default is both less controlled and less secure, because sensitive data ends up in many places with inconsistent protection. One owned, well-secured source of truth is safer than a dozen partial copies. This is what the Operating System provides.

Frequently asked questions

Where should family office data be stored?

Family office data should be stored in one owned, secure, family-controlled single source of truth, rather than scattered across advisors' individual systems. The location should give the family ownership of the record, control over who can access it, and security appropriate to its sensitivity. Advisors and tools connect to that home; they do not hold the master copy.

Is it safe to keep family wealth data in the cloud?

Modern cloud infrastructure can be very secure, and for most families the safety question is less about cloud versus on-premise than about ownership and access control. Cloud can deliver sovereignty when the family owns the data and controls who reaches it. The detail of that choice is covered in on-premise vs cloud for family wealth. --- **Explore security with Circle 26 →**

Share this essay
Share

The Coordinator

Our newsletter on the craft of running complex wealth.

Registers, decision rights, compliance calendars, and the work only a person can do. Twice a month, and no pitch.

Subscribe to The Coordinator