We handle data for financial advisors and insurance consultants — we understand the stakes. Here's exactly how we protect it.
All data is encrypted in transit using TLS 1.3. Every request between your browser and our servers travels over HTTPS — there's no unencrypted channel.
Data at rest is encrypted by Cloudflare's storage layer. We don't manage encryption keys ourselves — Cloudflare handles this transparently with AES-256.
Authentication uses session tokens, not passwords in transit. When you log in, we issue a short-lived bearer token. Your password is never stored in plain text — it's hashed with bcrypt before being saved.
Every API call is authenticated server-side. There's no client-side trust — even if someone manipulates the app in their browser, the server verifies every request independently.
When you use AI features (client insights, email drafts, message suggestions), relevant client data is sent to Anthropic's API to generate the response. This is processed in real time and not used to train Anthropic's models under our enterprise agreement.
We send only the minimum data needed for the task — typically the client's name, notes, and policy/relationship context. We do not send sensitive financial figures, ID numbers, or data unrelated to the specific AI task.
AI-generated content is always shown to you before anything is sent — you review and approve every message before it reaches a client.
In the unlikely event of a data breach or security incident, we will notify affected users by email within 72 hours of becoming aware of it, in accordance with applicable data protection laws.
If you discover a security vulnerability, please report it responsibly to [email protected]. We take all reports seriously and will respond within 48 hours.
Questions about how we handle your data?
Email us at [email protected] — we'll reply within one business day.