Security
Built for sensitive family information.
Mourning Guide is designed to store practical planning details your family may need, while avoiding categories of information that should stay with dedicated legal, medical, financial, or password-management providers.
Last updated: July 3, 2026
What we protect
Mourning Guide stores account information, family planning notes, final wishes, letters, trusted contacts, document locations, uploaded documents and photos, billing status, and memorial portal content when you choose to publish it.
Doctor contact entries are intended for practical directory information such as name, address, and phone number. Mourning Guide is not a medical records system and should not be used for diagnoses, treatment records, prescriptions, protected health records, or health-care directives that require separate legal handling.
What not to store
- Passwords, PINs, recovery codes, or one-time passcodes.
- Social Security numbers, full account numbers, or payment-card numbers.
- Medical records, diagnoses, prescriptions, or treatment history.
- Original legal documents that require an attorney, court, notary, or custodian.
Safeguards
- Authentication is handled by Clerk.
- Payment card collection is handled by Stripe; Mourning Guide does not store card numbers.
- Production secrets are stored in encrypted deployment environment variables.
- Account data is scoped by authenticated account membership checks.
- Security headers are used to reduce browser attack surface.
- Secret scanning, dependency checks, linting, type checking, and CodeQL are configured in CI.
Security reports
If you believe you found a security issue, email security@mourninguide.com. Please include the affected page or API route, steps to reproduce, and the impact you believe is possible.
Please do not publicly disclose a suspected vulnerability until we have had a reasonable chance to investigate and remediate it.
Independent review
We are preparing for an independent application security review as part of public launch hardening. We do not currently claim SOC 2, ISO 27001, HIPAA, or PCI certification.