Trust centre

Security and compliance, documented for your vendor review

You are handing us identity data about your customers. This page sets out exactly how it is encrypted, who can reach it, how long we keep it and how our information security program maps to the FTC Safeguards Rule. Where a control is still in progress, we say so.

Last reviewed December 2025 · Questions to support@verifydeceased.com

Where we stand

Frameworks and attestations

Our program is built against the rule our financial institution customers are actually examined against, and mapped to the frameworks your reviewers already work in.

Aligned

GLBA Safeguards Rule

Our information security program is built against 16 CFR Part 314, including a designated Qualified Individual, a written risk assessment, access controls, encryption, monitoring and an annual review.

In progress

SOC 2 Type II

We are working toward a SOC 2 Type II report covering Security, Availability and Confidentiality. We do not hold a completed report yet and we will not claim one until we do. Ask us for the current timeline and the interim control summary.

Mapped

NIST CSF 2.0

Controls are mapped to the NIST Cybersecurity Framework 2.0 functions so reviewers who work in NIST terms can cross walk our answers without a translation exercise.

Mapped

CIS Controls v8

System hardening and configuration baselines follow CIS Critical Security Controls v8 and vendor hardening guidance, with configuration drift checks on our production estate.

We do not hold a completed SOC 2 report today and we will not imply otherwise. If a completed report is a hard requirement for your procurement process, talk to us early and we will share our audit timeline and the interim control evidence we can provide in the meantime.

SOC 2 readiness

Exactly where we are on the path to a report

Most vendors say the words "in progress" and leave it there. Here is the actual sequence, what is finished, and what we are working on right now.

  1. Phase 1

    Security program documented

    Written information security program built against 16 CFR Part 314, with a designated Qualified Individual, a documented risk assessment and defined control ownership.

    Complete
  2. Phase 2

    Controls implemented and evidenced

    Encryption, access control, logging, change management, retention and incident response operating in production with the evidence trail an auditor needs to sample.

    Complete
  3. Phase 3

    Readiness assessment and gap remediation

    Independent review against the Security, Availability and Confidentiality criteria, with identified gaps tracked to closure on a risk based timeline.

    In progress
  4. Phase 4

    Type I report

    Point in time attestation that our controls are suitably designed. This is the first artefact we will be able to hand to a reviewer.

    Planned
  5. Phase 5

    Type II report

    Attestation over an observation window that the controls operated effectively, covering Security, Availability and Confidentiality.

    Planned
Controls

How your data is protected

Six control areas, each with the specifics rather than a reassuring adjective.

Encryption in transit and at rest

TLS 1.2 or higher on every connection and AES-256 encryption at rest across databases, object storage and backups.

  • TLS 1.2 minimum on all public endpoints, TLS 1.3 preferred, with weak ciphers disabled
  • AES-256 encryption at rest for databases, uploaded files, result files and backups
  • Encryption keys held in a managed key service with restricted access and rotation
  • HTTPS enforced end to end, including the API and file download links

Short, documented data retention

Records you submit are held only as long as needed to deliver and reconcile results, then deleted on a defined schedule.

  • Uploaded input files and result files are deleted on a defined schedule after delivery
  • Customers can request earlier deletion of a specific batch at any time
  • We do not sell, resell or license the records you submit to us
  • Your submitted records are not used to train or enrich data sold to anyone else

Access control and authentication

Least privilege access, multi factor authentication on administrative access, and API keys scoped per environment.

  • Role based access aligned to job function, granted on a least privilege basis
  • Multi factor authentication required for administrative and production access
  • API keys are scoped per environment and can be rotated or revoked by the customer
  • Joiner, mover and leaver process tied to HR events, with periodic access reviews

Logging, monitoring and testing

Security relevant events are logged and monitored, with recurring vulnerability scanning and annual penetration testing.

  • Authentication, privileged action and data access events are logged and retained
  • Recurring authenticated vulnerability scanning across application and infrastructure
  • Annual penetration testing, with findings tracked to closure on a risk based timeline
  • Patching and configuration baselines reviewed against CIS and vendor guidance

Incident response

A documented incident response plan with defined severities, escalation paths and customer notification commitments.

  • Documented plan covering detection, containment, investigation, recovery and review
  • Defined severity levels with named owners and escalation paths
  • Customer notification without undue delay where your data is affected
  • Post incident review feeds corrective actions back into the risk assessment

Permissible use and privacy

Death data is powerful. We contract for legitimate use only, and we contract our own providers to the same standard.

  • Customer agreements restrict use to legitimate purposes such as fraud prevention and claims
  • Sources are licensed or accessed under the certification program that governs them
  • Service providers are assessed before engagement and bound by written obligations
  • Privacy policy and processing terms are available to review before you sign
GLBA Safeguards Rule

Our control mapping to 16 CFR Part 314

The FTC Safeguards Rule requires covered financial institutions to maintain a documented information security program. Here is each requirement and what we do to meet it, so you can drop it straight into your own assessment.

CitationWhat the rule requiresWhat VerifyDeceased does
§ 314.4(a)Designate a Qualified Individual to oversee the information security programA named Qualified Individual owns the program, reports to leadership on program status, risks, incidents and testing, and has the authority and budget to act.
§ 314.4(b)Perform and document a written risk assessmentA written risk assessment with a documented methodology covers internal and external threats, likelihood and impact, and control gaps. It is refreshed at least annually and after material change.
§ 314.4(c)(1)Implement access controls and authenticationRole based least privilege access, multi factor authentication on administrative and production access, environment scoped API keys, and periodic access reviews tied to HR events.
§ 314.4(c)(2)Inventory data, systems and where customer information flowsWe maintain an inventory of the systems and stores that hold customer information, with data flow documentation covering upload, matching, delivery and deletion.
§ 314.4(c)(3)Encrypt customer information in transit and at restTLS 1.2 or higher in transit and AES-256 at rest across databases, uploaded files, result files and backups, with keys held in a managed key service.
§ 314.4(c)(4)Adopt secure development practices and change managementPeer reviewed changes, dependency and static analysis in the pipeline, hardened configuration baselines, and change records for production deployments.
§ 314.4(c)(5)Monitor and log authorised user activity and detect unauthorised accessSecurity relevant events including authentication, privileged actions and access to customer information are logged, retained and monitored for anomalies.
§ 314.4(c)(6)Maintain secure disposal and business continuity for customer informationEncrypted backups with restoration testing, defined recovery objectives, and scheduled secure deletion of submitted records once they are no longer needed.
§ 314.4(d)Test and monitor the effectiveness of safeguardsRecurring authenticated vulnerability scanning and annual penetration testing, with findings tracked to closure and fed back into the risk assessment.
§ 314.4(e)Train staff and provide security awarenessSecurity awareness training at onboarding and annually, role specific training for engineering and support, and phishing simulation with follow up.
§ 314.4(f)Oversee service providersProviders are assessed before engagement, bound by written security obligations including breach notification, and reassessed on a risk based cadence.
§ 314.4(h)Maintain a written incident response planA documented plan covering detection, containment, investigation, notification and post incident review, exercised at least annually.
§ 314.4(i)Report to the board or senior leadership at least annuallyThe Qualified Individual delivers a written annual report covering program status, risk assessment results, testing outcomes, incidents and recommended improvements.

This mapping describes our own information security program. It is provided to support your due diligence and is not legal advice. You remain responsible for your own Safeguards Rule obligations, including the oversight of us as a service provider under § 314.4(f).

Data lifecycle

What we keep, and for how long

The shortest honest answer to "what happens to our file after you match it". We do not sell, resell or license the records you send us, and we do not use them to enrich data we sell to anyone else.

DataRetentionNotes
Uploaded input filesDeleted on a defined schedule after results are deliveredEarlier deletion available on request for any specific batch.
Verification result filesAvailable for download for a limited window, then deletedDownload and keep your results inside your own retention policy.
Match and billing metadataRetained for the life of the account plus statutory record keepingRecord counts and charges only. No underlying identity fields.
Account and contact informationRetained for the life of the accountDeleted on request after account closure, subject to legal obligations.
Security and audit logsRetained for a defined period to support investigationRequired to meet monitoring and incident response obligations.
Encrypted backupsRotated out on the backup cycleBackups are encrypted and restoration is tested.

Deletion on request

You can request deletion of a specific batch at any time and we will confirm once it is done. Account level deletion is available on closure, subject to the billing and audit records we are legally required to retain.

Hosting and data residency

All customer data is processed and stored in United States regions, including backups. The named subprocessor list covering hosting, payments, transactional email and observability is provided in the security package.

Service providers

Subprocessors and vendor oversight

Under § 314.4(f) you are accountable for the providers we use. Every provider that can touch customer information is assessed before engagement, bound by written security obligations including breach notification, and reassessed on a risk based cadence.

PurposeData handledRegion
Cloud infrastructure and hostingUploaded records, result files, application dataUnited States
Payment processingBilling contact and card data, handled by the processorUnited States
Transactional emailAccount email address and notification contentUnited States
Error monitoring and observabilityOperational telemetry and diagnostic metadataUnited States

Providers are named in the security package rather than published here, so the list you receive is always the current one.

When something goes wrong

Incident response and continuity

A plan that only exists on paper is not a plan. Ours defines who acts, how fast, and what you hear from us.

Incident response

A documented plan covering detection, containment, investigation, recovery and post incident review, with defined severity levels, named owners and escalation paths. The plan is exercised at least annually.

Notifying you

If an incident affects your data we notify you without undue delay with what we know, what we are doing about it and what we need from you, then follow up with the outcome of the investigation and the corrective actions taken.

Backups and recovery

Backups are encrypted and restoration is tested, with defined recovery time and recovery point objectives for the systems that hold customer information. Continuity plans are reviewed after material change.

Our commitments

What you can count on

These are the commitments we make to every customer who trusts us with their data. If we cannot keep one of them, we will tell you rather than quietly change the wording.

  • Data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256
  • Access follows least privilege, and administrative access requires multi factor authentication
  • Records you submit are retained only as long as needed, then deleted on a defined schedule
  • We never sell, resell or license the records you send us
  • API keys are scoped per environment and can be rotated or revoked by you at any time
  • Infrastructure is monitored, patched and scanned, with annual penetration testing
  • All customer data is hosted in United States regions
  • We complete customer security questionnaires and join vendor review calls

Data handling

You submit only the identity fields needed to run a match. We process those records to return a result, then delete them on a defined schedule. We do not sell the records you send us and they never become part of a product we sell to someone else.

Permissible use

Death data is powerful, so it must be used well. We provide it for legitimate verification such as fraud prevention, claims validation and program integrity. Our terms restrict use to those purposes, and we expect customers to apply their own review before any irreversible action on a consumer account.

Vendor review

Everything in our security package

Most enterprise security reviews stall because the vendor answers slowly. Ask once and you get the whole set, plus a call with the person who owns our program.

  • Completed security questionnaire, or your own questionnaire returned
  • FTC Safeguards Rule (16 CFR Part 314) control mapping
  • Encryption, key management and data retention detail
  • Incident response and breach notification commitments
  • Business continuity, backup and restoration testing summary
  • Named subprocessor list and their security obligations
  • Most recent penetration test summary and remediation status
  • SOC 2 Type II readiness status and current timeline
Questions

Security and compliance questions

The eight questions that come up in every enterprise evaluation.

Are you SOC 2 certified?

Not yet, and we will not say otherwise. We are working toward a SOC 2 Type II report covering Security, Availability and Confidentiality, and we are happy to share the current timeline and our interim control summary. In the meantime our information security program is built and documented against the FTC Safeguards Rule, which is the standard our financial institution customers are examined against.

How do you support GLBA Safeguards Rule obligations?

Our program follows 16 CFR Part 314. We have a designated Qualified Individual, a written risk assessment refreshed at least annually and after material change, access controls with multi factor authentication, encryption in transit and at rest, logging and monitoring, secure development and change management, service provider oversight, a documented incident response plan, and an annual written report to leadership. We publish the full control mapping on our security page.

How is our data encrypted?

Every connection uses TLS 1.2 or higher, with TLS 1.3 preferred and weak ciphers disabled. Data at rest is encrypted with AES-256 across databases, uploaded files, result files and backups. Encryption keys are held in a managed key service with restricted access and rotation.

How long do you keep the records we submit?

Only as long as needed to deliver and reconcile results. Uploaded input files and result files are deleted on a defined schedule, and you can request earlier deletion of a specific batch at any time. We do not sell, resell or license the records you send us, and we do not use them to enrich data we sell to anyone else.

Will you complete our vendor security questionnaire?

Yes. Our team completes customer questionnaires and joins vendor review calls as a standard part of onboarding. Ask for the security package and you will receive our control mapping, encryption and retention detail, incident response commitments, business continuity summary, subprocessor list and the most recent penetration test summary.

What happens if there is a security incident?

We maintain a documented incident response plan with defined severity levels, named owners and escalation paths. If your data is affected we notify you without undue delay with what we know, what we are doing and what we need from you. Every incident is followed by a post incident review that feeds corrective actions back into our risk assessment.

Where is our data hosted?

In the United States. Cloud infrastructure, backups and processing all stay within US regions. The named subprocessor list, including hosting, payments, email and observability, is provided in the security package.

Can we restrict how results are used inside our organization?

Yes, and we encourage it. API keys are scoped per environment and can be rotated or revoked by you at any time, and access to results in the dashboard is controlled per account. Our terms also restrict use of results to legitimate purposes such as fraud prevention, claims validation and program integrity.

Running a security or vendor review?

Our team will complete your questionnaire, walk through the control mapping and answer anything this page did not cover.