Keeping Your Resting Data Safe

We don’t expect you to access our site 24/7. We know there are other things you’d rather be doing (we suggest underwater basket weaving). When you’re not accessing it, we store your data using AES-256 encryption. Everything is stored with a uniquely-derived key as recommended by NIST Special Publication 800-132.

And yes, we mean everything. Every field that holds personal information, including your name and email address, is encrypted. Every. Single. One.

Securing Data in Transit

Any and all communication between you and Sure Legacy is secured. We encrypt communication via SSL using 2048-bit certificates and require SSL on all communications for perfect forward secrecy. We’re like ninjas but more technological. So, even cooler ninjas.

Keeping Our Site Secure

They say you’re your own worst critic, and while we try not to put ourselves down, we definitely make sure to keep ourselves on our toes when it comes to security. This means we regularly audit and patch our data security to ensure we’re one step ahead of security updates. 

Our security experts and commercial security services allow us to consistently test ourselves to verify our site’s security. Call us a teacher’s pet if you want, but we don’t stop until we’re an A+ student.

Controlling Access to Your Information

We put your information under so many locks and keys that it makes Fort Knox look like a cheap bike lock. Strict internal procedures limit Sure Legacy employees or administrators from accessing your data beyond basic information necessary to help give you access to your account (i.e., triggering confirmation emails) and restricting access to your account in urgent circumstances (i.e., limiting or removing a Deputy’s access). 

Our employees never see your plan information or uploaded documents. Additionally, we log and audit all accesses to your account, whether by you, an administrator, or your Deputies.

Two-Factor Authentication

Picture this: An elite team of hackers has found your password and is on the way to steal your family secrets. How will your secret banana pudding recipe survive?

Thanks to two-factor authentication, those crooks won’t ever get into your account. Enable this option, and we’ll send you a unique code through your phone whenever you sign in to your Sure Legacy account from a new device or browser. It’s an extra layer of security!

HIPAA

Much like The Go-Go’s (or Hillary Duff if you’re an after-life-planning-focused millennial), our lips are sealed when it comes to your health information. Sure Legacy is compliant under the Health Insurance Portability and Accountability Act of 1996 (HIPAA), which means we manage the privacy and security of your information under formal and rigorous requirements designed to protect sensitive personal and health information. 

We hold ourselves to this high standard and ensure that any external parties through which your information is transmitted are liable for protecting the privacy and security of your information to the same extent.

SOC 2

Sure Legacy has secured an independent CPA’s report and certification after undergoing a Type II Service Organization Control 2 (SOC 2) examination. The report is an assurance that Sure Legacy has established and follows strict information security policies and procedures. This also means we provide independent, third-party verification that our operations meet or exceed defined levels of processes and controls for the security of customer data.