Security

Enterprise-grade security.

Insurance data is sensitive. We built Insuralix with security as a foundational requirement, not an afterthought.

SOC 2 Type II Compliant

Annual third-party audits verify our security controls, availability, and confidentiality practices.

AES-256 Encryption at Rest

All data stored on our platform is encrypted using AES-256, the same standard used by financial institutions.

TLS 1.3 in Transit

All data transmitted between your systems and Insuralix is protected with TLS 1.3 encryption.

Isolated Processing

Policy documents are analyzed in isolated, ephemeral environments. No cross-tenant data access is possible.

No Model Training on Your Data

Your policy documents and agency data are never used to train or improve our AI models. Your data stays yours.

Role-Based Access Control

Fine-grained permissions let you control exactly who on your team can see what. Producer-level isolation is available.

99.9% Uptime SLA

Our infrastructure runs on enterprise-grade cloud providers with multi-region redundancy.

Regular Penetration Testing

We engage independent security firms to conduct penetration tests on a quarterly basis.