Security & Compliance

At Memorial Intelligence, we understand that funeral homes handle deeply personal and sensitive information. Protecting that data is a responsibility we take seriously. Our platform is designed with security, privacy, and reliability at its core.

This page outlines current application safeguards. It is not a certification statement, service-level commitment, or guarantee of security or regulatory compliance.


Data Hosting & Infrastructure

Memorial Intelligence uses managed cloud infrastructure and managed database services with separate production and development environments.

  • Production and development environments are fully separated
  • Production data is managed separately from development data
  • Development tools cannot directly modify production data
  • Database access is not intended to be publicly exposed

These architectural controls are intended to reduce the risk of accidental exposure and unauthorized access.


Multi-Tenant Data Isolation

The application is designed to separate tenant data through organization-scoped access controls.

  • Organization-scoped checks are applied in application workflows
  • Data access is restricted at the application level
  • Users can only access records associated with their assigned funeral home(s)

These controls are intended to limit users to records associated with their assigned funeral home(s).


Encryption & Data Protection

We use industry-standard encryption to protect data at all times:

  • TLS 1.2+ encryption for all data in transit
  • AES-256 encryption for data at rest
  • Secure session handling and hardened cookies
  • Security headers including CSP, HSTS, and X-Frame-Options

Access Controls & Authentication

Access to Memorial Intelligence is protected through layered controls:

  • Role-based access permissions
  • Password complexity requirements
  • Rate limiting on authentication attempts
  • CSRF protection on 155+ forms
  • Secure session management and timeout handling

Access controls are intended to limit sensitive functionality to authorized users.


Secrets & Credential Management

All sensitive credentials are securely managed:

  • API keys and credentials are stored as encrypted secrets
  • Sensitive credentials are managed outside application source code
  • Secrets are not exposed in logs or public forks
  • Production secrets are isolated from development secrets

This includes payment credentials and third-party integrations.


Payments & Financial Security

Memorial Intelligence integrates with Stripe for payment processing.

  • Payment information is handled directly by Stripe
  • Memorial Intelligence does not store credit card numbers
  • Stripe operates under PCI-DSS compliance standards

Backups & Data Recovery

To protect against accidental loss or system issues:

  • Production databases support point-in-time recovery
  • Rollback capabilities are available if needed
  • Platform architecture is designed for minimal downtime during updates

Incident Response Commitment

While no system can guarantee zero risk, we are committed to responsible handling of any security concerns.

In the event of a suspected security incident, we will:

  • Investigate promptly
  • Restrict access as needed
  • Review logs and affected systems
  • Notify impacted customers if applicable
  • Take corrective action to prevent recurrence

Continuous Improvement

Security is an ongoing process. Memorial Intelligence regularly reviews:

  • Application-level safeguards
  • Access controls
  • Platform updates and best practices

As the platform grows, additional security measures and third-party reviews may be introduced.


Questions?

If you have questions about security, privacy, or data protection, please contact us directly. We are happy to discuss our safeguards and how they support your funeral home's responsibilities.


SSN Privacy Protection Policy

We maintain a dedicated Social Security Number Privacy Protection Policy that describes how SSN data is collected, encrypted, accessed, and disposed of. Customers should consult their own legal advisers regarding applicable privacy requirements.

View SSN Privacy Protection Policy