Skip to main content

Insurance data security and compliance

Policy Balance Hub is built from the ground up with the controls insurance agencies need to meet GLBA, NAIC, and state regulatory requirements — and the audit evidence to prove it.

Security and compliance controls

Encryption in Transit and for Stored Credentials

Traffic to and from the platform is encrypted in transit, and the third-party credentials you hand us are encrypted at the application layer before they are stored.

  • TLS for all data in transit
  • Fernet (AES-128-CBC with HMAC-SHA256) encryption for the credentials we store on your behalf — mailbox passwords and integration secrets
  • Uploaded files are stored under a key namespaced to your agency, validated on every read
  • Secrets managed outside application code

Where Your Data Lives

The platform is self-hosted. Your agency's data sits in infrastructure we operate directly, not in a third-party managed data platform.

  • Application, PostgreSQL database and object storage all run on infrastructure we operate
  • Every subprocessor that touches your data is named in our privacy policy, together with what it receives
  • Stripe handles payment cards — card numbers are entered directly into Stripe and never stored by us
  • Anthropic receives carrier-statement text only after names and government identifiers have been redacted
  • For the hosting region, our current subprocessor list, or a completed security questionnaire, email privacy@policybalancehub.com

Multi-Tenant Data Isolation

Your data is isolated from other agencies at the database level. There is no cross-tenant data access.

  • Every database query is scoped by agency_id
  • PostgreSQL row-level security enforces tenant isolation
  • Per-request tenant context set at the database session level
  • Automated tests verify cross-tenant isolation

PII Protection

Personal identifying information is handled with care and is never sent to external AI processing.

  • Names and SSNs are redacted before any AI processing
  • A PII redaction layer strips sensitive fields automatically
  • No personal data is sent to external AI services
  • Data minimization principles applied throughout

SOC 2 Type II (Being Pursued)

We are pursuing SOC 2 Type II. We are not yet certified, and we don't represent ourselves as certified.

  • No auditor engaged and no observation period started yet — we will not publish a target date we cannot back
  • Controls mapped to the SOC 2 Trust Service Criteria
  • Ongoing internal monitoring of control effectiveness

Insurance Regulatory Alignment

Our controls are designed to align with the regulations that govern insurance agencies. These are self-assessed alignments, not independent certifications.

  • GLBA Safeguards Rule — encryption, access controls, and audit trails for financial data
  • NAIC Insurance Data Security Model Law (Model 668) — risk assessment and incident response practices
  • CCPA / CPRA — consumer data access, deletion, and opt-out considerations for California residents
  • NIST Cybersecurity Framework 2.0 — risk-based security program alignment
  • PCI DSS — payment card handling delegated to Stripe (PCI Level 1 service provider)

Security Scanning in CI/CD

Our security posture is evaluated through automated scanning in the build pipeline, with third-party penetration testing planned ahead of our SOC 2 audit.

  • Dependency vulnerability scanning in CI/CD
  • Secret scanning to catch leaked credentials before deploy
  • Container image scanning in the pipeline
  • Penetration testing planned before the SOC 2 audit period

Audit Logging

Every state-changing action in the system is logged with full context for compliance and forensics.

  • Immutable audit trail for data modifications
  • User, timestamp, and action recorded for every change
  • Audit logs retained and exportable for compliance
  • Export capability for regulatory requests

Compliance frameworks we align to

Policy Balance Hub implements technical controls designed to align with the regulatory standards that govern insurance agencies handling sensitive policyholder data. These are self-assessed control alignments, not independent certifications.

GLBA
Gramm-Leach-Bliley Act
SOC 2
Type II (pursuing)
CCPA/CPRA
California Privacy Rights
NAIC 668
Data Security Model Law
NIST CSF
Cybersecurity Framework 2.0
PCI DSS
via Stripe

Ready to stop drowning in spreadsheets?

See how Policy Balance Hub can automate premium reconciliation for your agency. Start the trial in minutes — or request a personalized walkthrough.

14-day free trial (up to 100 policies, 3 users). No credit card required.