Security and access

Protected records. Customer-controlled access.

Files uploaded through the member portal are encrypted while being transferred and while stored. You decide what to upload, who to invite, and which records each authorized person may access.

01

Encrypted during transfer and storage

The third-party storage platform protects file transfers with Transport Layer Security (TLS) and stores files using AES-256 encryption. These controls apply to the storage environment used for EnsureLoc member records.

02

Certified storage infrastructure

The third-party provider reports that its storage infrastructure uses independently audited data centers meeting SOC 2 and ISO 27001 standards. Those certifications belong to the provider and its infrastructure—not to EnsureLoc as an organization.

03

Authenticated, permission-based access

Portal access requires an authenticated user account. Members invite trusted people, select which records they may access, and may change or remove permissions through the portal. Additional login verification may be available depending on account configuration.

04

Activity reporting

The portal supports user and file activity reporting for actions such as access, sharing, and downloads. The scope and availability of reporting depend on the provider’s current configuration and service features.

05

Redundancy and backup controls

The provider’s published security controls include redundant storage, backup processes, and network safeguards. These controls reduce risk but do not make any online service immune from outages, loss, misuse, or security incidents.

06

Separate customer workspaces

Each customer account is provisioned with its own separate records workspace. Access is governed by the authenticated accounts and access permissions associated with that workspace.

What EnsureLoc provides

  • Provisioning of the member portal account and standard record organization
  • Reasonable account-administration controls for the EnsureLoc service
  • Technical account support
  • Response to suspected issues involving EnsureLoc account provisioning or service administration

What each member controls

  • Passwords, email accounts, devices, and recovery methods
  • Use of any additional login-verification features offered by the portal
  • Which lawful records are uploaded
  • Who is invited and which records are shared
  • Permission reviews, access removal, and independent backups
100% hands-off customer-record policy. EnsureLoc employees do not open, view, read, inspect, edit, rename, organize, modify, delete, interpret, advise on, or assist with the contents of individual customer records. Account and technical support is provided without accessing record contents.
Access after incapacity or death. EnsureLoc does not determine legal authority, grant discretionary access, or release customer files to someone merely because that person claims to be a relative, executor, beneficiary, caregiver, representative, or other interested party. Access must come from permissions established by the customer or through valid legal process handled by the appropriate provider or legal authority.
Third-party technology disclosure. EnsureLoc uses a third-party file-storage and sharing service. Technical controls and certifications described on this page belong to that provider and its infrastructure. EnsureLoc does not claim those certifications as its own, does not own the underlying storage infrastructure, and does not guarantee that provider features will remain unchanged.
No online service is risk-free. No storage platform can be guaranteed completely secure or continuously available. Use a strong, unique password; enable additional login verification when offered; protect your email account and devices; review sharing permissions regularly; and keep separate copies of records essential to health, safety, legal rights, or immediate recovery.