For Employers · For your legal team
The page to forward to legal, security, or procurement. The short version: employees own their accounts, employers see aggregate numbers only, and we don’t claim certifications we don’t hold.
Aggregate numbers only: how many employees activated, overall checklist progress, and which tools get used across the group. The employer reporting surface has no path to an individual’s plan, documents, answers, or activity. That boundary is how the reporting is built, not a policy promise layered on top.
The employee. They create their own account with their work email, and what they put in it belongs to them. The employer pays for access; it doesn’t acquire the contents. MORTL doesn’t sell personal information.
Accounts and saved planning data stay with the employee. Premium features lapse to the free tier, and the someone-just-died path stays free for everyone permanently. Nothing gets handed to the employer and nothing gets deleted out from under the employee.
The privacy policy lists the categories and the service-provider roles: hosting and storage, authentication, payment processing, and transactional email. It applies to employer-sponsored accounts exactly as it does to individual ones.
Document uploads are stored encrypted at rest by the storage provider and connections use HTTPS. MORTL also tells users directly not to store Social Security numbers, account passwords, or seed phrases in planning notes; the guidance in the product is written to keep secrets out of it.
No, and we won’t pretend otherwise. MORTL is a small company. We answer security questionnaires honestly and quickly, we review DPA requests, and if a control you need is missing we’ll tell you before you sign, not after.
MORTL investigates, fixes, and notifies the program contact and affected users as applicable law requires. We don’t bury bad news; honesty about death extends to honesty about problems.
Approving your work-email domain. Employees activate themselves by signing in with a work email; there’s no roster upload, no SSO integration, and no software to install. If your security review needs more than that, bring it to the founding call.