TrustedSite monitored
The TrustedSite badge links to current site-security verification and monitoring context.
Verify the site →Heritage Passport helps you work with passports, vital records, lineage facts, addresses, and payment events. The security model is deliberately plain: protect uploads, limit access, avoid reselling sensitive data, and use established infrastructure for storage, payments, and abuse prevention.
The TrustedSite badge links to current site-security verification and monitoring context.
Verify the site →Stripe collects and processes card details. Heritage Passport does not store full card numbers.
Account, case, and document records use private storage with encryption in transit and at rest.
You can request access, correction, export, or deletion, subject to legal retention requirements.
Uploads use short-lived signed addresses, permitted file types, size limits, and a storage path that binds each object to the signed-in user, case, and document. Finalizing an upload re-checks case ownership and stored-file metadata before the document is registered.
Uploading and finalizing a document requires a signed-in user before any storage object is registered.
Server checks confirm the case belongs to the user and the upload path matches that user, case, and document.
Every private file view is permission checked and uses a signed link that expires after 60 seconds.
Uploads are restricted to supported image and PDF types, size limits, and abuse controls.
We do not claim SOC 2, HIPAA, ISO 27001, or another certification unless current proof supports it.
Our server must read a document when you ask the product to extract facts or check the file.
Card entry and payment processing happen through Stripe, not a Heritage Passport card database.
Heritage Passport is not an advertising broker for identity records. Sensitive personal information is collected to provide the service, not sold or shared for cross-context behavioral advertising, and can be deleted on request subject to legal retention requirements.
Authentication, Postgres database, and Storage infrastructure for account, case, document, and vault records.
Payment processing and signed payment-event verification; Stripe also handles card data directly.
Document contents are sent only when the document-reading workflow runs to extract the facts that feature needs.
Bot and abuse checks on public account-entry flows when Turnstile keys are configured.
After account closure, the Privacy Policy provides a 30-day download period before production deletion. Immediate document deletion can be requested.
Deleted production data may remain in rolling backups for up to seven additional days.
Payment records may be retained for tax, accounting, fraud, and legal obligations.
This page summarizes our security posture in plain English. The controlling terms for collection, sharing, retention, deletion, and account rights are the Privacy Policy and Terms of Service.
Read the Privacy Policy or Terms.