Security & trust

Your book of business stays yours.

RiskVantage handles loss runs, claims, and policy data for competing brokerages. This page explains how that data is stored, separated, and accessed — and where our compliance program stands today.

Data security

Data is encrypted on the wire and on disk, and is shared only with the subprocessors that run the service (listed under Privacy).

  • All traffic between your browser, the web app, and the API is encrypted with TLS (HTTPS only).
  • Databases and uploaded files (loss runs, claims exports) live on managed cloud services with encryption at rest.
  • Uploads go directly to object storage over short-lived, single-file signed URLs — files are never staged on a shared web server.
  • Secrets and API keys are held in the hosting platform's secret store, never in source code.

Tenant isolation

Every brokerage is a separate tenant. There is no cross-broker visibility, by design (ADR-001).

  • Every row of client, claim, upload, and insight data carries a tenant id and is read and written only through tenant-scoped queries.
  • Your tenant is resolved from your authenticated organization on every request — it cannot be chosen from the URL or a form field.
  • Insured client users (your policyholders) are additionally scoped to a single client account within your tenant.
  • Demo data is synthetic, clearly labelled, and stored under its own tenant — it never mixes with live broker data.

Authentication

Identity is handled by Clerk; we never store passwords.

  • Sign-in, session management, and organization membership are provided by Clerk.
  • Single sign-on and multi-factor authentication are supported through Clerk's configuration for your organization.
  • Access to a brokerage workspace is by invitation only. Inviting insured client users is admin-only today; broader admin-vs-member role checks across the workspace are on the Phase 6 roadmap.
  • Platform operators use a separate, allow-listed identity — there is no shared admin login.

Compliance status

In progress

Formal certifications are on the roadmap; controls are being built to that standard now.

  • SOC 2 readiness (audit logging, access reviews, encryption verification) is planned as a dedicated workstream.
  • Structured, correlated request logs exist today; Sentry error tracking and end-to-end request tracing are rolling out in Phase 6.
  • We will publish sub-processor and data-retention details alongside the Privacy Policy.
  • Ask us for our current security questionnaire responses — we answer them for every prospective brokerage.

Privacy

Coming soon

A full Privacy Policy is being finalized.

  • We process broker and policyholder data solely to provide the RiskVantage service to the brokerage that uploaded it.
  • Data is not sold or shared with other tenants. Subprocessors we rely on today: Clerk (identity), Anthropic (AI insight generation), Resend (email), and Sentry (error reports, when enabled). The full list and their terms will be in the Privacy Policy.
  • Until the Privacy Policy is published, contact us with any data-handling question and we will answer in writing.

Security questions?

We are happy to walk your IT or compliance team through the architecture, complete a vendor questionnaire, or share the current state of the roadmap items above.

Talk to us
Security & Trust