1. Overview
At MortemCare, protecting the sensitive data of funeral homes and families is a top priority. We are committed to maintaining the confidentiality, integrity, and availability of all information stored on our platform. Our approach to security combines technology, operational controls, and responsible data management practices.
2. Data Protection
- All information, including deceased records, personal data, and payment details, is encrypted in transit using HTTPS (TLS 1.2+).
- Sensitive fields such as passwords and payment tokens are stored securely using industry-standard encryption and hashing techniques.
- User access is protected by secure authentication and session management protocols.
3. Infrastructure Security
MortemCare runs on reputable cloud infrastructure with built-in redundancy and automatic scaling.
- Data is hosted in secure environments managed by trusted providers that comply with international data protection standards.
- Firewalls, network segmentation, and continuous monitoring tools are implemented to detect and block unauthorized access.
- Regular system updates and patching are performed to minimize vulnerabilities.
4. Access Control
- Access to MortemCare systems is strictly limited and role-based.
- Every access attempt is logged and monitored for unusual activity.
- All administrative accounts use strong passwords and multi-factor authentication (MFA).
5. Payment Security
We do not directly store or process card information.
- Payments are securely handled through our third-party partners such as Paystack, which are PCI-DSS compliant.
- Payment data transmitted between users and Paystack is encrypted and tokenized for additional protection.
6. Data Backup and Recovery
- Regular backups are performed to ensure data can be recovered in case of an outage or data loss.
- Backups are stored securely in multiple regions with strict access control.
- Disaster recovery procedures are reviewed periodically to ensure business continuity.
7. Monitoring and Incident Response
- We maintain proactive monitoring systems to identify and address potential threats quickly.
- Logs are continuously analyzed for suspicious patterns.
- In the event of a security incident, we follow a defined response plan that includes containment, investigation, user notification, and remediation.
8. User Responsibility
- Use strong, unique passwords for your MortemCare account.
- Do not share login credentials with unauthorized individuals.
- Report any suspicious activity or potential security concerns to our team immediately.
9. Continuous Improvement
Security is not a one-time setup, it’s an ongoing commitment.
- We continuously evaluate and improve our security posture based on emerging threats and technology best practices.
- Regular internal reviews are conducted to identify and address potential weaknesses in our systems and processes.
10. Contact Us
If you suspect a security issue or have a question about how we protect your data, please contact:
Email: [email protected]