Security & Privacy
Your most sensitive family information deserves more than a password. Here is how we protect it.
Encrypted Uploads
Files are protected in transit with HTTPS/TLS and stored using encrypted storage. Documents are never served via public URLs — access requires authentication.
Controlled Access
Only the account owner and approved trusted contacts can access private information. Access levels are set by you — Viewer, Family Admin, Emergency Contact, or Memorial Contributor.
Private Share Codes
Families can share a private access code instead of sending sensitive files through text messages or email. Codes are hashed and stored — never as plain text. They can be revoked at any time.
No Casual Admin Browsing
Our system is designed so support staff cannot casually browse uploaded documents. Administrative access is limited, logged, and used only for security or support reasons.
HIPAA-Inspired Privacy Controls
HIPAA-inspiredFinalKeepSake uses HIPAA-inspired privacy principles for sensitive documents, including access controls, encryption, audit logs, and least-privilege permissions. Formal HIPAA compliance and BAA support may be added for healthcare or professional partners in a future version.
Row-Level Security
TechnicalEvery database table uses Row-Level Security policies. Users can only read and write their own records. There is no way to query another user's data — even with a valid session token.
Short-Lived Signed URLs
TechnicalPrivate files are never served via permanent URLs. All file downloads use signed URLs that expire in 5 minutes — too short for a leaked link to be useful.
Zero-Knowledge Future Option
Coming soonFuture advanced privacy mode may use client-side encryption so files are encrypted before upload and cannot be read by the platform — not even by FinalKeepSake staff.
Audit Trail
Every access is recorded
Our platform maintains a complete audit log of sensitive actions so you always know who accessed what and when.
Legal Disclaimer
FinalKeepSake is not a law firm and does not provide legal, financial, medical, or estate-planning advice. Uploading a document does not create, validate, or replace a legal will. Users should consult qualified professionals for legal documents and estate planning.
FinalKeepSake uses HIPAA-inspired privacy principles. This platform is not HIPAA certified. No Business Associate Agreement (BAA) is currently offered. Formal HIPAA compliance may be added in future versions for healthcare or professional partner accounts.