Skip to main content

Insurance data security and compliance

Policy Balance Hub is built from the ground up with the controls insurance agencies need to meet GLBA, NAIC, and state regulatory requirements — and the audit evidence to prove it.

Security and compliance controls

Encryption at Rest and in Transit

All data is encrypted using industry-standard algorithms to protect your sensitive information.

  • AES-256 encryption for data at rest
  • TLS for all data in transit
  • Fernet symmetric encryption for sensitive application fields
  • Secrets managed outside application code

Multi-Tenant Data Isolation

Your data is isolated from other agencies at the database level. There is no cross-tenant data access.

  • Every database query is scoped by agency_id
  • PostgreSQL row-level security enforces tenant isolation
  • Per-request tenant context set at the database session level
  • Automated tests verify cross-tenant isolation

PII Protection

Personal identifying information is handled with care and is never sent to external AI processing.

  • Names and SSNs are redacted before any AI processing
  • A PII redaction layer strips sensitive fields automatically
  • No personal data is sent to external AI services
  • Data minimization principles applied throughout

SOC 2 Type II (In Progress)

We are pursuing SOC 2 Type II. We are not yet certified, and we don't represent ourselves as certified.

  • SOC 2 Type II in progress — target Q3 2026
  • Controls mapped to the SOC 2 Trust Service Criteria
  • Ongoing internal monitoring of control effectiveness

Insurance Regulatory Alignment

Our controls are designed to align with the regulations that govern insurance agencies. These are self-assessed alignments, not independent certifications.

  • GLBA Safeguards Rule — encryption, access controls, and audit trails for financial data
  • NAIC Insurance Data Security Model Law (Model 668) — risk assessment and incident response practices
  • CCPA / CPRA — consumer data access, deletion, and opt-out considerations for California residents
  • NIST Cybersecurity Framework 2.0 — risk-based security program alignment
  • PCI DSS — payment card handling delegated to Stripe (PCI Level 1 service provider)

Security Scanning in CI/CD

Our security posture is evaluated through automated scanning in the build pipeline, with third-party penetration testing planned ahead of our SOC 2 audit.

  • Dependency vulnerability scanning in CI/CD
  • Secret scanning to catch leaked credentials before deploy
  • Container image scanning in the pipeline
  • Penetration testing planned before the SOC 2 audit period

Audit Logging

Every state-changing action in the system is logged with full context for compliance and forensics.

  • Immutable audit trail for data modifications
  • User, timestamp, and action recorded for every change
  • Audit logs retained and exportable for compliance
  • Export capability for regulatory requests

Compliance frameworks we align to

Policy Balance Hub implements technical controls designed to align with the regulatory standards that govern insurance agencies handling sensitive policyholder data. These are self-assessed control alignments, not independent certifications.

GLBA
Gramm-Leach-Bliley Act
SOC 2
Type II (pursuing)
CCPA/CPRA
California Privacy Rights
NAIC 668
Data Security Model Law
NIST CSF
Cybersecurity Framework 2.0
PCI DSS
via Stripe

Ready to stop drowning in spreadsheets?

See how Policy Balance Hub can automate premium reconciliation for your agency. Start the trial in minutes — or request a personalized walkthrough.

14-day free trial (up to 100 policies, 3 users). No credit card required.