How we protect your family’s information.
Your data is encrypted at rest with AES-256 and protected in transit with TLS. Access is scoped through roles and family relationships, and service providers process data needed to operate the features you use. Our SOC 2 Type II readiness work is underway.
Last Updated: August 20, 2026
1. Our security philosophy
Families share things with us they wouldn’t share with anyone else: end-of-life wishes, estate planning notes, stories about people they’ve lost. We treat that as a duty, not a feature. Every product decision starts from a simple question: if this were my family’s information, would I trust the way it’s being handled?
This page explains, in plain English, how we protect that information today and where we’re investing next.
2. How we protect family data
BestFarewell is built around the idea that a family is a group of people with different roles and different levels of access. You decide who joins your family, what role they have, and what they can see. Sensitive items like wills, trusts, beneficiary details, and advance directives are scoped to the family they belong to and the people you’ve invited into it.
For normal signed-in access, our database uses row-level security policies that evaluate account, family, and organization relationships. These policies add an authorization layer at the data boundary instead of relying on the interface alone.
3. How uploaded documents are stored
When you upload a will, trust, insurance policy, photograph, voice recording, or any other file, it’s stored in Supabase Storage with object-level access policies that match your family’s permissions. Files are encrypted at rest with AES-256 and protected in transit with TLS.
Uploaded documents are not intended for public search indexing. We do not sell them or use them to train our own models. When you choose an AI-powered feature, the content needed for that request may be processed by a service provider as described in our Privacy Policy.
You can manage or delete documents through the product. Our Privacy Policy explains how deletion requests, legal retention, and provider backup cycles are handled.
4. Who can access family or member data
Family access is controlled by the people you invite and the roles you give them. BestFarewell also uses service providers to operate functions such as hosting, authentication, payments, communications, analytics, and optional AI features.
Staff permissions are scoped to operational responsibilities, such as maintaining or supporting the Service. We do not sell personal data for third-party marketing or use customer content to train our own models.
We may disclose information when required by law or when needed to protect rights and safety, as described in our Privacy Policy.
5. Encryption basics
In transit
Connections between your device and BestFarewell are protected with TLS while data travels across the network.
At rest
Once your data reaches our servers, it’s stored with AES-256 encryption. If a hard drive in a data center were somehow removed, the data on it would be unreadable without the encryption keys, which are managed separately by our infrastructure provider.
6. Payment security via Stripe
We use Stripe to host payment-card entry and process payments. BestFarewell receives payment status and limited transaction metadata, not your full card number or CVC, and we do not store raw card data on our servers.
Payment details are handled under the processor’s security and privacy terms.
7. Account security
Account sign-in is handled by our authentication provider. BestFarewell does not store your password in plain text. Signed-in requests are validated on the server and access is scoped through account, family, and organization permissions.
If you suspect your account has been accessed without your permission, contact us immediately at security@bestfarewell.com.
8. Service providers
We use service providers for infrastructure, authentication, payments, communications, analytics, support, and optional AI features. These providers process data on our behalf only as needed to deliver the Service and are managed according to the information and functions in scope.
9. Working with security researchers
If you’re a security researcher and believe you’ve found an issue, we want to hear about it.
Please report findings to security@bestfarewell.com with steps to reproduce, the affected URL or endpoint, and any supporting detail.
We do not currently run a formal bug bounty program. Please do not access, alter, or retain another person’s data while investigating a potential issue.
10. Data retention
We keep your data for as long as your account is active so that your family’s information is there when you or your loved ones need it. You can update or delete content at any time from inside the app.
Deletion timing depends on the type of data, applicable legal obligations, and service-provider backup cycles. Our Privacy Policy provides more detail. You can request a copy of your data or ask questions about retention by emailing privacy@bestfarewell.com.
11. SOC 2 Type II readiness
We are preparing for an independent SOC 2 Type II examination. We do not currently have a SOC 2 report, and we do not describe BestFarewell as SOC 2 certified. We are documenting, operating, and testing the controls we expect an independent auditor to evaluate once the examination begins.
We’ll update this page when the independent examination is complete and a report is available. If you’re evaluating BestFarewell and need a vendor security questionnaire today, write to security@bestfarewell.com to ask what current documentation is available.
12. Reporting a security concern
If you spot something that looks wrong, or if you’re worried about the security of your account, email security@bestfarewell.com. Include the affected account or URL and the steps you observed.
For non-security questions, our general support inbox is team@bestfarewell.com.
Related policies
For the full detail on how we collect and handle personal information, see our Privacy Policy. For the terms that govern your use of BestFarewell, see our Terms of Service.