Please wait
We are fetching the details of Member ID: N/A
Close
No Results Icon
No results found for member ID: 999999

Please recheck the ID entered, and search again.

Close
We couldn't verify that you're human based on the security check

Please try again to complete the verification process

findeREC Inc Security

One POWERFUL Solution

ISO 27001
ISO 27001 Compliance

findeREC aligns with ISO 27001 standards by implementing robust encryption, role-based access controls, and structured incident response protocols. These measures support the confidentiality, integrity, and availability of Member data across our platform.

SOC 2 Compliance
SOC 2 Compliance

findeREC aligns with SOC 2 principles by implementing comprehensive audit logging, secure development practices, and rigorous access management controls. These safeguards help ensure the confidentiality, integrity, and availability of Member data across our platform.

PCI-DSS Compliance
PCI-DSS Compliance

findeREC does not store or process payment data and therefore this requirement is not applicable. However, all payments are securely handled by a third-party provider that is fully PCI-DSS compliant.

Effective Date: October 1, 2025

Last Updated: November 9, 2025

At findeREC Inc. ("we," "our," "us"), protecting your information is at the core of our mission. The eREC Service is designed to securely manage emergency contact information while giving Members control over when, where, and how their data is accessed. findeREC is built with privacy-by-design and implements governance and security controls suitable for emergency-readiness data. This statement summarizes findeREC's U.S. security compliance position under ISO 27001, SOC2, and PCI-DSS and the controls implemented to support privacy and security for families, schools, organizations/businesses, and emergency responders.

SECURITY COMPLIANCE POSITION AT A GLANCE

  • ISO 27001 Compliant. findeREC is compliant and aligns with ISO 27001 principles through encryption, access controls, and incident response protocols.
  • SOC 2 Compliant. findeREC is compliant and aligns audit logging, secure development, and access management.
  • PCI-DSS: Compliance Not Applicable. findeREC does not store or process payment data directly and therefore this requirement is not applicable. However, all payments are securely handled by a third-party provider that is fully PCI-DSS compliant.

INTERNATIONAL STANDARD FOR INFORMATION SECURITY MANAGEMENT - ISO 27001

ISO 27001 is a globally recognized framework for managing and protecting sensitive information. It helps organizations identify risks, implement controls, and continuously improve their security posture. It enforces risk management, data protection, and security governance to builds trust with users and partners and support regulatory compliance.

  • findeREC is compliant and aligns with ISO 27001 principles through encryption, access controls, and incident response protocols

SYSTEM AND ORGANIZATION CONTROLS - SOC 2

SOC 2 is a U.S.-based auditing standard that evaluates how well a company protects customer data across five key areas: security, availability, processing integrity, confidentiality, and privacy. Internal controls for data security and reliability are to be implemented to demonstrate accountability and safeguards for cloud-based services.

  • findeREC is compliant and aligns audit logging, secure development, and access management

PAYMENT CARD INDUSTRY DATA SECURITY STANDARD - PCI-DSS

PCI-DSS sets strict rules for handling credit card data to prevent fraud and breaches. It's required for any service that stores, processes, or transmits payment information to secure payment data and prevent unauthorized access and therefore reduce risk of financial data breaches.

  • findeREC does not store or process payment data directly. All payments are securely handled by a third-party provider that is fully PCI-DSS compliant.
  • findeREC's platform architecture reflects PCI principles—such as encryption, secure authentication, and limited data access—even beyond payment flows

DATA ENCRYPTION

When Members sign in to findeREC, connection is protected by HTTPS using TLS encryption—just like online banking. This means everything entered is securely transmitted and shielded from unauthorized access. TLS provides us 256-bit encryption, keeping personal information private and confidential every step of the way.

ACCOUNT AUTHENTICATION

To protect our Members, all findeREC accounts are private and can only be accessed using a valid Username and password. Members are required to create their own password, which should be kept strictly confidential. Once signed on, Members can manage their information.

As an added layer of protection:

  • Passwords must be at least 10 characters long and include at least one number (0-9) or special character (e.g., @, #, $, !).
  • Multi-Factor Authentication (MFA) is also used to verify identity during login. This means that even if someone obtains a password, they cannot access the account without a second form of verification—such as a code sent to a phone or email.

These safeguards help ensure that emergency contact information remains secure and accessible only to Members and those trusted individuals.

HOW EMERGENCY CONTACT INFORMATION IS BE ACCESSED

findeREC is designed to make emergency contact information available—only to the right people, only when it's needed, and only with your permission. That is the core service offering.

eREC MEMBER ID

Every account is issued a unique system generated eREC Member ID, which acts as a secure key to retrieve emergency contact details. Members control how and when their information is shared, with multiple layers of protection in place.

SMART SECURITY FEATURES

Google ReCAPTCHA

findeREC uses reCAPTCHA to quietly detect and block bots or automated scraping attempts. This ensures that only real people—not machines—can access emergency records.

Security Access Code (SEC)

Members can change their Member ID anytime by setting a custom Security Access Code. This gives full control to revoke or update access—even if the ID was previously shared.

WAYS EMERGENCY CONTACT INFORMATION IS ACCESSED

1. Manual Entry via findeREC.com

Authorized individuals and first responders can enter a Member ID directly on the findeREC website to view emergency contact details, only if permitted by the Member.

2. QR Code Scan via eREC Member Card

Each Member has a digital or printed eREC card with a QR code. Scanning it directs the user to findeREC.com and reveals emergency contact information the Member has chosen to share.

3. Organizational Lists (RBAC)

Verified group administrators (e.g., schools or businesses) can use interactive lists to retrieve emergency contact information. Access is strictly controlled through role-based authentication.

4. Member-Initiated Sharing

Members can copy and share their eREC link via text, email, or other platforms. The link opens directly to their emergency contact profile on findeREC.com. Access can be revoked or updated anytime using the Security Access Code.

NETWORK PROTECTION

findeREC uses a layered "defense-in-depth" approach to protect our platform from unauthorized access and cyber threats. This strategy is powered by a suite of advanced Azure security tools and best practices.

  • Threat Detection & Prevention: Azure's intelligent threat detection services continuously monitor for suspicious behavior, intrusion attempts, and known attack patterns. Automated alerts and real-time analytics help us respond quickly to potential risks.
  • Segmentation & Isolation: Our network is segmented to limit exposure and contain threats. Sensitive systems are isolated behind secure zones, with tightly controlled access pathways.
  • Zero Trust Principles: Access to internal systems is governed by identity verification, least-privilege access, and continuous monitoring—ensuring that no one is trusted by default, even inside the network.

This multi-layered security model ensures that findeREC's infrastructure remains resilient, responsive, and secure—so families and partners can trust that their data is protected at every level.

FIREWALL PROTECTION

We deploy multiple layers of firewall security—including Azure Network Security Groups (NSGs), Web Application Firewalls (WAF), and perimeter firewalls—to monitor, filter, and control incoming and outgoing traffic. These firewalls help block malicious activity, prevent unauthorized access, and enforce strict traffic rules across our infrastructure.

Microsoft Azure offers powerful tools to help secure cloud-based applications and protect sensitive data. Two key components in findeREC's security architecture are Web Application Firewall (WAF) and Azure Key Vault.

WEB APPLICATION FIREWALL (WAF)

Azure WAF protects web applications from common threats and vulnerabilities—like SQL injection, cross-site scripting (XSS), and bot attacks.

  • Real-time threat detection: Monitors and filters HTTP/HTTPS traffic to block malicious requests.
  • Custom rules: Allows fine-tuned control over what traffic is allowed or denied.
  • DDoS protection: Helps mitigate distributed denial-of-service attacks.
  • Global coverage: Integrated with Azure Front Door and Application Gateway for scalable, edge-based protection.

AZURE KEY VAULT

Azure Key Vault securely stores and manages sensitive information—such as API keys, passwords, certificates, and cryptographic secrets.

  • Centralized secret management: Keeps credentials out of code and config files.
  • Access control: Uses Azure Active Directory to enforce role-based access.
  • Audit logging: Tracks who accessed what and when, supporting compliance and incident response.
  • Automatic rotation: Supports secret versioning and renewal for enhanced security hygiene.

Together, Azure WAF and Key Vault help findeREC maintain a strong security posture—protecting both the platform and the sensitive data entrusted by families, schools, and emergency responders.

API SECURITY WITH JWT (JSON WEB TOKEN)

JSON Web Tokens (JWT) are a widely adopted standard for securing APIs and authenticating users in modern web applications. JWT is a cornerstone of findeREC's API security strategy, helping ensure that data access is authenticated, authorized, and protected across all endpoints.

A JWT is a compact, digitally signed token that securely transmits identity and authorization information between a client and server. It allows APIs to verify who is making a request—without storing session data on the server.

  • Authentication: After a user logs in, the system issues a JWT. This token is included in future API requests to verify the user's identity.
  • Authorization: JWTs can carry role-based permissions, helping APIs determine what data or actions the user is allowed to access.
  • Tamper-Proof: Each token is cryptographically signed, ensuring its integrity and preventing unauthorized modifications.
  • Stateless & Scalable: Because JWTs are self-contained, they reduce server load and support scalable, distributed systems.

INPUT VALIDATION IN LARAVEL: REQUEST VALIDATION & BLADE ESCAPING

Input validation is a critical part of web application security—it ensures that data coming into your system is clean, expected, and safe to process.

Laravel Request Validation

Laravel provides powerful tools to validate incoming data from forms, APIs, or user input before it's used or stored. This prevents malformed or malicious data from entering your system, reducing the risk of SQL injection, logic errors, or broken workflows.

Blade Escaping

Blade is Laravel's templating engine. It automatically escapes output to prevent Cross-Site Scripting (XSS) attacks.

Together, Laravel's request validation and Blade escaping form a strong defense against common web vulnerabilities—keeping findeREC secure and end users protected.

CONTINUOUS ANTI-VIRUS PROTECTION AND MONITORING

At findeREC, we take proactive steps to safeguard our systems against malware, viruses, and other cyber threats. Our infrastructure is protected by enterprise-grade anti-virus software that is continuously updated to detect and block the latest known threats.

  • Real-Time Monitoring: Our anti-virus tools scan files, processes, and network activity in real time to identify suspicious behavior before it can cause harm.
  • Automatic Updates: We maintain the latest virus definitions and threat intelligence feeds, ensuring our systems are equipped to defend against emerging risks.
  • Multi-Layered Defense: Anti-virus protection is part of a broader security strategy that includes firewalls, encryption, access controls, and secure development practices.
  • Endpoint Security: All endpoints—including servers and workstations—are monitored and protected to prevent unauthorized access or infection.

This ongoing vigilance helps ensure that findeREC remains a safe and trusted platform for families, schools, and emergency responders.

If findeREC detects unusual activity or suspects a potential security issue with an account, we'll temporarily suspend access as a precaution—and notify you immediately by email.

  • If it's a false alarm (like multiple failed login attempts due to a forgotten password), our team will quickly help restore access.
  • If there's a real concern (such as someone else gaining access to your credentials), we'll guide the Member through creating a stronger, more secure password—or, if needed, help close the account entirely.

Safety and privacy are our top priority. We're here to support every step of the way.

AUTOMATIC SESSION TIMEOUT FOR ADDED SECURITY

To help keep information safe, findeREC will automatically log out after a period of inactivity. This protects accounts when users step away from their device without logging off.

  • If a session times out, simply log back in to continue.
  • For added security, always log out manually when you're done using findeREC—especially on shared or public devices.

Privacy is our priority, and these safeguards help ensure your emergency contact data stays protected.

BACKUP & DISASTER RECOVERY

At findeREC, we prioritize business continuity and data protection through a robust Backup & Disaster Recovery (BDR) strategy. Our approach is designed to minimize downtime, safeguard sensitive information, and ensure rapid recovery in the event of a disruption.

RISK ASSESSMENT: IDENTIFYING POTENTIAL THREATS

We continuously assess and monitor risks that could impact system availability or data integrity, including:

  • Cybersecurity threats such as data breaches, ransomware, or unauthorized access
  • System failures due to hardware malfunctions, software bugs, or misconfigurations
  • Natural disasters like fires, floods, or power outages affecting data centers
  • Human error, including accidental deletion or mismanagement of critical data
  • Third-party service disruptions that could impact cloud or network infrastructure

RECOVERY STRATEGIES: BUILT FOR RESILIENCE

To ensure rapid recovery and uninterrupted service, findeREC implements multiple layers of protection:

  • Automated Backups: Regular, encrypted backups of all critical data are stored in secure, geographically distributed locations.
  • Cloud Redundancy: Core systems are hosted in the cloud with built-in redundancy, ensuring high availability and fault tolerance.
  • Failover Infrastructure: In the event of a primary system failure, traffic is automatically rerouted to standby environments to maintain service continuity.
  • Recovery Time Objectives (RTO) & Recovery Point Objectives (RPO): We define and test clear recovery benchmarks to minimize data loss and downtime.
  • Routine Testing: Disaster recovery plans are regularly tested and updated to reflect evolving threats and infrastructure changes.

With these safeguards in place, findeREC is prepared to respond quickly and effectively to unexpected events—protecting the trust of our users and the integrity of their emergency contact information.

HOW TO KEEP findeREC ACCOUNT SECURE

Your privacy and safety matter—and you play a key role in protecting your emergency contact information. Here's how to stay secure:

Smart Practices at Home or Work

  • Choose a strong password and never share it with anyone.
  • Keep your devices protected with up-to-date antivirus, anti-spyware, and firewall software.
  • Install operating system updates regularly (e.g., Windows, macOS) to patch security vulnerabilities.
  • Review your sharing settings to make sure your emergency contacts and authorized viewers are accurate and current.
  • Report suspicious activity immediately—especially if you think someone accessed your account or you receive a fake email pretending to be findeREC.

Safe Access While Traveling Or Using Public Computers

  • Use trusted devices whenever possible. If you're at a library, café, or using a friend's computer, ask if it has current security software and a firewall.
  • Never leave your session unattended. If you step away, log out first.
  • Always log out when finished and close the browser window. For extra protection, clear the browser's cache.

By following these tips, you help ensure that your emergency contact information stays private, secure, and accessible only to those you trust.

BEWARE OF PHISHING ATTEMPTS

Phishing is a form of email fraud where scammers pose as trusted organizations—like banks, credit card companies, or even government agencies—to trick you into sharing personal information such as your username, password, or account details. These messages often look official and claim they need access to your account for security, verification, or urgent updates.

Important: findeREC will never ask you to share your password or login credentials—by email, phone, or any other method.

If you ever receive a message from someone claiming to be from findeREC and asking for access to your account or emergency contact information, do not respond. Instead, report it to us immediately so we can investigate and protect your account. Your security is our priority—and together, we can keep your information safe.

All Your Emergency Contacts. One Powerful Solution

With findeREC…
Employers, Schools, Childcare Centers, Family, Hospitals, Churches, Local Authorities, and more can locate emergency contacts and next of kin,
whenever needed.
Quick Links
eREC Evolution
Why I Need eREC
How eREC Works
Features
Security
Privacy Policy
Terms of Service
Disclaimer
About eREC
Follow or Contact Us
Call 1-888-514-eREC (3732) 1-404-806-9540
Mailing Address
PO BOX 162942
ATLANTA, GA 30321
Email
Contact Us
© 2025 Copyright All right reserved
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy

eREC Terms of Service

Effective Date: October 1, 2025
Last Updated: October 1, 2025

Welcome to the electronic Record of Emergency Contacts (“eREC”), an online service provided by findeREC Inc. (“Company,” “we,” “us,” or “our”). By accessing or using the eREC website located at www.findeREC.com (the “Website”) and related services (collectively, the “Service”), you agree to be bound by these Terms of Service (the “Agreement”).

If you do not agree, please do not use the Service. If you register as a member or co-member (“Member”), your enrollment confirms acceptance of these Terms.

1. Eligibility

  • You must be at least 18 years old to use the Service.
  • By registering, you represent that you have the authority and capacity to enter into this Agreement.
  • Membership is void where prohibited by law.

2. Membership & Term

  • Basic Membership: Free.
  • Premium Membership: Paid, valid for one (1) year from enrollment date.
  • Membership continues until expiration, cancellation, or termination.

3. Cancellations & Refunds

  • Cancellation by Member: You may cancel at any time via your account or in writing to findeREC.
  • Cancellation by findeREC: We may suspend or terminate your account if you violate this Agreement. No refund is provided if terminated for breach.
  • Refunds: Premium Members may request a full refund within 30 days of initial enrollment by emailing cancellations@findeREC.com.

4. Account Security

  • You are responsible for maintaining the confidentiality of your username and password.
  • You agree to notify us immediately of any unauthorized access.
  • Each account is for individual use and may not be shared without authorization.

5. eREC ID & Security Access Code

  • Upon enrollment, you will receive a unique eREC ID number, which may be displayed on your Member card.
  • You may also create a Security Access Code to further restrict access to your emergency contact information. You are responsible for sharing this code with trusted individuals or organizations.

6. Group Membership

  • Organizations (e.g., employers, schools) may establish group memberships with discount offers.
  • Group IDs allow eREC to identify new Members within a group.
  • Groups are not responsible for paying individual membership fees unless explicitly agreed in writing.

7. Member Content & Responsibilities

  • You are solely responsible for the information you provide, including emergency contact details.
  • You must obtain permission from individuals before listing them as emergency contacts.
  • Prohibited content includes but is not limited to:
    • Hate speech, threats, or harmful material.
    • False, misleading, or illegal content.
    • Unauthorized solicitation, spam, or advertising.
    • Exploitative or abusive content.

8. Intellectual Property

  • findeREC Inc. owns all rights to the Website and Service, including trademarks, logos, and software.
  • You may not copy, modify, or distribute our proprietary materials without written consent.

9. Copyright Policy

If you believe your copyrighted material has been used without permission, contact us at:
PO Box 196942, Atlanta, GA 30321
Please include all required DMCA notice elements.

10. Limitation of Liability

  • To the fullest extent permitted by law, findeREC Inc. is not liable for indirect, incidental, or consequential damages (including lost profits).
  • Our total liability is limited to the amount paid by you for the Service during your current membership term.

11. Indemnification

You agree to indemnify and hold harmless findeREC Inc., its affiliates, and employees from any claims or damages arising out of:

  • Your use of the Service,
  • Your violation of this Agreement, or
  • Your inclusion of third-party information without consent.

12. Disputes & Governing Law

This Agreement is governed by the laws of the State of Georgia, USA. Any disputes will be resolved in the state or federal courts located in Georgia.

13. Entire Agreement

This Agreement constitutes the full understanding between you and findeREC Inc. If any part is found unenforceable, the remaining provisions remain in effect.

eREC Disclaimer

  • The Service provides a platform for storing and sharing emergency contact information.
  • findeREC Inc. does not verify the accuracy of information provided by Members.
  • Members are solely responsible for obtaining consent from individuals listed as emergency contacts.
  • findeREC Inc. is not responsible for:
    • Locating emergency contacts,
    • Technical errors, interruptions, or security breaches,
    • The actions or conduct of Members or third parties,
    • Loss, damage, or injury resulting from use of the Website or Service.
  • The Service is provided “as-is” without warranties of any kind, including fitness for a particular purpose.
  • We do not guarantee specific outcomes or results from use of the Service.

eREC Privacy Policy

Effective Date: October 1, 2025
Last Updated: October 1, 2025

findeREC Inc. (“we,” “our,” “us”) respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, and protect your data, including rights available to residents of California and the European Union/European Economic Area (EU/EEA).

1. Information We Collect

  • Personal Information: Name, address, email, phone number, emergency contact details.
  • Financial Information: Payment details (for Premium Membership).
  • Demographic & Technical Information: Age, location, browsing activity, IP address, device details.

2. How We Use Information

  • To provide, maintain, and improve the Service.
  • To process transactions and manage Membership.
  • To display authorized emergency contact information to other Users (with your consent).
  • To communicate with you regarding account status, security, or updates.
  • To comply with legal obligations and enforce our Terms of Service.

3. Sharing of Information

  • With trusted service providers (payment processors, hosting, customer support, analytics).
  • With law enforcement or regulators, if required by law.
  • In the case of merger, acquisition, or transfer of ownership.
  • We do not sell your personal information to third parties.

4. Security

  • SSL encryption for data transmission.
  • Financial data is securely processed by third-party providers and not stored on our servers.
  • We use administrative, technical, and physical safeguards to protect your information.

5. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access, correct, or delete your personal information.
  • Restrict or object to processing of your data.
  • Withdraw consent at any time.
  • Receive a copy of your data in a portable format (data portability).
  • Requests may be submitted to privacy@findeREC.com. We will respond in accordance with applicable law.

6. Data Retention

We retain information only as long as necessary for the purposes described, unless a longer retention is required by law (e.g., tax, accounting, or security obligations).

7. GDPR (EU/EEA) Compliance

If you are located in the European Union/European Economic Area, the following applies:

  • Legal Basis for Processing: We process your personal data based on one or more of the following:
    • Your consent (e.g., displaying emergency contacts).
    • Contract necessity (e.g., fulfilling your Membership).
    • Legal obligations (e.g., compliance with tax laws).
    • Legitimate interests (e.g., improving security and services).
  • Your Rights under GDPR:
    • Right to be informed about how your data is used.
    • Right of access to your data.
    • Right to rectification (correction of inaccurate data).
    • Right to erasure (“right to be forgotten”).
    • Right to restrict processing.
    • Right to data portability.
    • Right to object to processing.
    • Right not to be subject to automated decision-making without meaningful human input.
  • International Transfers: If we transfer data outside the EU/EEA (e.g., to U.S. servers), we use appropriate safeguards such as Standard Contractual Clauses (SCCs).
  • To exercise GDPR rights, contact us at privacy@findeREC.com.

8. CCPA/CPRA (California) Compliance

If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) provide specific rights:

  • Right to Know: You may request details about the personal data we collect, use, and disclose.
  • Right to Delete: You may request deletion of personal data, subject to legal exceptions.
  • Right to Opt-Out: You may opt-out of the sale or sharing of your personal information. (We do not sell personal data.)
  • Right to Non-Discrimination: You will not be discriminated against for exercising your privacy rights.
  • Sensitive Personal Information: We do not use sensitive categories (e.g., health data, precise geolocation) for profiling or targeted advertising.
  • Requests can be submitted to privacy@findeREC.com or by mail to:
    PO Box 196942, Atlanta, GA 30321
    Verification may be required before fulfilling your request.

9. Children’s Privacy

Our Service is not directed to individuals under 18. We do not knowingly collect personal information from children. If we learn that a child under 18 has provided personal information, we will delete it promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. If significant changes are made, we will provide notice by posting on the Website or emailing Members at least 30 days before the changes take effect.