Enterprise Compliance

Compliance & Data Protection

Everything your legal, compliance, and procurement teams need to evaluate ObituaryMonitor for enterprise deployment.

AES-256
Encryption at Rest
TLS 1.3
Encryption in Transit
CCPA
Privacy Compliant
GDPR
Ready

Privacy Regulations

How we comply with data protection laws

CCPA
California Consumer Privacy Act

California Residents

  • Right to Know: Request information about data collection
  • Right to Delete: Request deletion of personal data
  • Right to Opt-Out: We do not sell personal information
  • Non-Discrimination: No service degradation for exercising rights
GDPR
General Data Protection Regulation

EEA/UK Residents

  • Lawful Basis: Contract performance or legitimate interest
  • Data Subject Rights: Access, rectification, erasure, portability
  • DPO Available: dpo@obituarymonitor.com
  • SCCs: Standard Contractual Clauses for international transfers

Security Practices

How we protect your data

Important Note

ObituaryMonitor has not undergone a SOC 2 audit. The security certifications listed in the Infrastructure Partners section below are held by our vendors, not by ObituaryMonitor directly. We implement security controls aligned with industry best practices.

🔐

Encryption at Rest

AES-256 encryption for all stored data

🔒

Encryption in Transit

TLS 1.3 for all connections

🔑

Password Security

bcrypt hashing with high work factor

👤

Access Control

Role-based permissions (RBAC)

📋

Audit Logging

Comprehensive activity tracking

⏱️

Session Security

HTTP-only cookies, auto-timeout

Infrastructure Partners

Third-party certifications (held by vendors)

VendorServiceCertificationNotes
NetlifyApplication Hosting
SOC 2 Type II
Edge hosting with automatic DDoS protection
NeonDatabase
SOC 2 Type II
PostgreSQL with encryption at rest
StripePayment Processing
PCI DSS Level 1
We never store credit card data
TwilioSMS Notifications
SOC 2 Type II
Secure message delivery
PostmarkEmail Delivery
SOC 2 Type II
DKIM/SPF authenticated email

* These certifications are held by the respective vendors, not by ObituaryMonitor.

Data Retention

How long we keep your data

Data TypeRetention Period
Account DataActive account + 30 days after deletion
Watch List DataActive + 1 year archived
Match HistorySubscription + 2 years
Audit Logs7 years (legal compliance)
Payment Records7 years (financial regulations)
Security Logs90 days

Available Documentation

Request compliance documents for your review

On Request

Data Processing Agreement (DPA)

Standard contractual clauses for data processing. Required for GDPR compliance.

Request Document →
On Request

Business Associate Agreement (BAA)

For HIPAA-covered entities handling protected health information.

Request Document →
Download

Security Whitepaper

Comprehensive overview of our security architecture and practices.

Download PDF →
On Request

Subprocessor List

Complete list of third-party vendors who process customer data.

Request Document →
On Request

Security Questionnaire

We can complete CAIQ, SIG, or custom security questionnaires.

Request Document →
Public

Privacy Policy

Our complete privacy policy covering data collection and use.

View Document →

Need Compliance Documentation?

Our team is ready to help with DPAs, BAAs, security questionnaires, and any other compliance documentation your organization requires.