Your customers' data, treated like ours.
We built InsuraMate AI for an insurance agency, so we knew on day one that customer data and call recordings had to be locked down end to end.
One agency per deployment
Single-tenant isolation, no exceptions. Every InsuraMate AI deployment serves exactly one agency. No shared databases between customers, no shared model fine-tuning across tenants. What happens in your tenant stays in your tenant.
Field-level encryption for sensitive data
On top of the standard at-rest and in-transit encryption (AES-256 / TLS 1.2+), the most sensitive customer fields are individually encrypted with their own permission gates. Reading them requires both the right role and a logged justification.
Built on AWS and Google Cloud
We use Amazon Web Services and Google Cloud for the hosting, processing and machine-learning infrastructure the service runs on. Managed services handle storage, compute and databases. Both are named as subprocessors in your services agreement.
Full audit log, attached to every call
Every read or write the AI makes against your AMS or CRM is logged and attached to the originating call. Open the call, see the trail: 'looked up customer X, wrote note Y, created task Z.' No black-box behavior.
PII-redacted logs
We run centralized monitoring and structured logs for reliability and debugging. PII is automatically redacted before anything lands in those logs. Engineers troubleshooting an issue never see customer data they shouldn't.
Passwordless and SSO sign-in
Your team logs in with passwordless email links or with their existing Google or Microsoft account. We provision and de-provision admin access from your workplace identity provider, so leavers lose access automatically.
Secrets in a managed vault
API keys, OAuth tokens, AMS credentials: none of it is stored in our database. Everything sits in a managed secrets vault with rotation, access logging, and least-privilege checkout.
Phone and call security
Voice traffic runs over carrier-grade SIP through Twilio, with signed media and verified caller ID. Call recordings, when enabled, are retained on a configurable schedule and can be purged on request.
Insurance-aware compliance
We build to support your obligations under GLBA and the FTC Safeguards Rule, and we respect state-level insurance privacy rules. If your agency has specific contractual requirements, raise them on the call and we will tell you straight what we can and cannot sign today.
Have a security questionnaire?
Send it over. Our founder answers security questionnaires personally, and you will deal with him rather than a vendor portal.
Email us your questionnaireTalk to us about your stack.
Tell us your AMS, your phone setup, and your compliance constraints. We'll show you a call in our demo workspace and confirm where your AMS stands.