GLBA Safeguards Rule
Our information security program is built against 16 CFR Part 314, including a designated Qualified Individual, a written risk assessment, access controls, encryption, monitoring and an annual review.
You are handing us identity data about your customers. This page sets out exactly how it is encrypted, who can reach it, how long we keep it and how our information security program maps to the FTC Safeguards Rule. Where a control is still in progress, we say so.
Our program is built against the rule our financial institution customers are actually examined against, and mapped to the frameworks your reviewers already work in.
Our information security program is built against 16 CFR Part 314, including a designated Qualified Individual, a written risk assessment, access controls, encryption, monitoring and an annual review.
We are working toward a SOC 2 Type II report covering Security, Availability and Confidentiality. We do not hold a completed report yet and we will not claim one until we do. Ask us for the current timeline and the interim control summary.
Controls are mapped to the NIST Cybersecurity Framework 2.0 functions so reviewers who work in NIST terms can cross walk our answers without a translation exercise.
System hardening and configuration baselines follow CIS Critical Security Controls v8 and vendor hardening guidance, with configuration drift checks on our production estate.
We do not hold a completed SOC 2 report today and we will not imply otherwise. If a completed report is a hard requirement for your procurement process, talk to us early and we will share our audit timeline and the interim control evidence we can provide in the meantime.
Most vendors say the words "in progress" and leave it there. Here is the actual sequence, what is finished, and what we are working on right now.
Written information security program built against 16 CFR Part 314, with a designated Qualified Individual, a documented risk assessment and defined control ownership.
Encryption, access control, logging, change management, retention and incident response operating in production with the evidence trail an auditor needs to sample.
Independent review against the Security, Availability and Confidentiality criteria, with identified gaps tracked to closure on a risk based timeline.
Point in time attestation that our controls are suitably designed. This is the first artefact we will be able to hand to a reviewer.
Attestation over an observation window that the controls operated effectively, covering Security, Availability and Confidentiality.
Six control areas, each with the specifics rather than a reassuring adjective.
TLS 1.2 or higher on every connection and AES-256 encryption at rest across databases, object storage and backups.
Records you submit are held only as long as needed to deliver and reconcile results, then deleted on a defined schedule.
Least privilege access, multi factor authentication on administrative access, and API keys scoped per environment.
Security relevant events are logged and monitored, with recurring vulnerability scanning and annual penetration testing.
A documented incident response plan with defined severities, escalation paths and customer notification commitments.
Death data is powerful. We contract for legitimate use only, and we contract our own providers to the same standard.
The FTC Safeguards Rule requires covered financial institutions to maintain a documented information security program. Here is each requirement and what we do to meet it, so you can drop it straight into your own assessment.
| Citation | What the rule requires | What VerifyDeceased does |
|---|---|---|
§ 314.4(a) | Designate a Qualified Individual to oversee the information security program | A named Qualified Individual owns the program, reports to leadership on program status, risks, incidents and testing, and has the authority and budget to act. |
§ 314.4(b) | Perform and document a written risk assessment | A written risk assessment with a documented methodology covers internal and external threats, likelihood and impact, and control gaps. It is refreshed at least annually and after material change. |
§ 314.4(c)(1) | Implement access controls and authentication | Role based least privilege access, multi factor authentication on administrative and production access, environment scoped API keys, and periodic access reviews tied to HR events. |
§ 314.4(c)(2) | Inventory data, systems and where customer information flows | We maintain an inventory of the systems and stores that hold customer information, with data flow documentation covering upload, matching, delivery and deletion. |
§ 314.4(c)(3) | Encrypt customer information in transit and at rest | TLS 1.2 or higher in transit and AES-256 at rest across databases, uploaded files, result files and backups, with keys held in a managed key service. |
§ 314.4(c)(4) | Adopt secure development practices and change management | Peer reviewed changes, dependency and static analysis in the pipeline, hardened configuration baselines, and change records for production deployments. |
§ 314.4(c)(5) | Monitor and log authorised user activity and detect unauthorised access | Security relevant events including authentication, privileged actions and access to customer information are logged, retained and monitored for anomalies. |
§ 314.4(c)(6) | Maintain secure disposal and business continuity for customer information | Encrypted backups with restoration testing, defined recovery objectives, and scheduled secure deletion of submitted records once they are no longer needed. |
§ 314.4(d) | Test and monitor the effectiveness of safeguards | Recurring authenticated vulnerability scanning and annual penetration testing, with findings tracked to closure and fed back into the risk assessment. |
§ 314.4(e) | Train staff and provide security awareness | Security awareness training at onboarding and annually, role specific training for engineering and support, and phishing simulation with follow up. |
§ 314.4(f) | Oversee service providers | Providers are assessed before engagement, bound by written security obligations including breach notification, and reassessed on a risk based cadence. |
§ 314.4(h) | Maintain a written incident response plan | A documented plan covering detection, containment, investigation, notification and post incident review, exercised at least annually. |
§ 314.4(i) | Report to the board or senior leadership at least annually | The Qualified Individual delivers a written annual report covering program status, risk assessment results, testing outcomes, incidents and recommended improvements. |
This mapping describes our own information security program. It is provided to support your due diligence and is not legal advice. You remain responsible for your own Safeguards Rule obligations, including the oversight of us as a service provider under § 314.4(f).
The shortest honest answer to "what happens to our file after you match it". We do not sell, resell or license the records you send us, and we do not use them to enrich data we sell to anyone else.
| Data | Retention | Notes |
|---|---|---|
| Uploaded input files | Deleted on a defined schedule after results are delivered | Earlier deletion available on request for any specific batch. |
| Verification result files | Available for download for a limited window, then deleted | Download and keep your results inside your own retention policy. |
| Match and billing metadata | Retained for the life of the account plus statutory record keeping | Record counts and charges only. No underlying identity fields. |
| Account and contact information | Retained for the life of the account | Deleted on request after account closure, subject to legal obligations. |
| Security and audit logs | Retained for a defined period to support investigation | Required to meet monitoring and incident response obligations. |
| Encrypted backups | Rotated out on the backup cycle | Backups are encrypted and restoration is tested. |
You can request deletion of a specific batch at any time and we will confirm once it is done. Account level deletion is available on closure, subject to the billing and audit records we are legally required to retain.
All customer data is processed and stored in United States regions, including backups. The named subprocessor list covering hosting, payments, transactional email and observability is provided in the security package.
Under § 314.4(f) you are accountable for the providers we use. Every provider that can touch customer information is assessed before engagement, bound by written security obligations including breach notification, and reassessed on a risk based cadence.
| Purpose | Data handled | Region |
|---|---|---|
| Cloud infrastructure and hosting | Uploaded records, result files, application data | United States |
| Payment processing | Billing contact and card data, handled by the processor | United States |
| Transactional email | Account email address and notification content | United States |
| Error monitoring and observability | Operational telemetry and diagnostic metadata | United States |
Providers are named in the security package rather than published here, so the list you receive is always the current one.
A plan that only exists on paper is not a plan. Ours defines who acts, how fast, and what you hear from us.
A documented plan covering detection, containment, investigation, recovery and post incident review, with defined severity levels, named owners and escalation paths. The plan is exercised at least annually.
If an incident affects your data we notify you without undue delay with what we know, what we are doing about it and what we need from you, then follow up with the outcome of the investigation and the corrective actions taken.
Backups are encrypted and restoration is tested, with defined recovery time and recovery point objectives for the systems that hold customer information. Continuity plans are reviewed after material change.
These are the commitments we make to every customer who trusts us with their data. If we cannot keep one of them, we will tell you rather than quietly change the wording.
You submit only the identity fields needed to run a match. We process those records to return a result, then delete them on a defined schedule. We do not sell the records you send us and they never become part of a product we sell to someone else.
Death data is powerful, so it must be used well. We provide it for legitimate verification such as fraud prevention, claims validation and program integrity. Our terms restrict use to those purposes, and we expect customers to apply their own review before any irreversible action on a consumer account.
Most enterprise security reviews stall because the vendor answers slowly. Ask once and you get the whole set, plus a call with the person who owns our program.
The eight questions that come up in every enterprise evaluation.
Not yet, and we will not say otherwise. We are working toward a SOC 2 Type II report covering Security, Availability and Confidentiality, and we are happy to share the current timeline and our interim control summary. In the meantime our information security program is built and documented against the FTC Safeguards Rule, which is the standard our financial institution customers are examined against.
Our program follows 16 CFR Part 314. We have a designated Qualified Individual, a written risk assessment refreshed at least annually and after material change, access controls with multi factor authentication, encryption in transit and at rest, logging and monitoring, secure development and change management, service provider oversight, a documented incident response plan, and an annual written report to leadership. We publish the full control mapping on our security page.
Every connection uses TLS 1.2 or higher, with TLS 1.3 preferred and weak ciphers disabled. Data at rest is encrypted with AES-256 across databases, uploaded files, result files and backups. Encryption keys are held in a managed key service with restricted access and rotation.
Only as long as needed to deliver and reconcile results. Uploaded input files and result files are deleted on a defined schedule, and you can request earlier deletion of a specific batch at any time. We do not sell, resell or license the records you send us, and we do not use them to enrich data we sell to anyone else.
Yes. Our team completes customer questionnaires and joins vendor review calls as a standard part of onboarding. Ask for the security package and you will receive our control mapping, encryption and retention detail, incident response commitments, business continuity summary, subprocessor list and the most recent penetration test summary.
We maintain a documented incident response plan with defined severity levels, named owners and escalation paths. If your data is affected we notify you without undue delay with what we know, what we are doing and what we need from you. Every incident is followed by a post incident review that feeds corrective actions back into our risk assessment.
In the United States. Cloud infrastructure, backups and processing all stay within US regions. The named subprocessor list, including hosting, payments, email and observability, is provided in the security package.
Yes, and we encourage it. API keys are scoped per environment and can be rotated or revoked by you at any time, and access to results in the dashboard is controlled per account. Our terms also restrict use of results to legitimate purposes such as fraud prevention, claims validation and program integrity.
Our team will complete your questionnaire, walk through the control mapping and answer anything this page did not cover.