Trust & Security

Your data doesn't leave. Your clients stay protected.

Coverflow safely handles highly sensitive insurance data including policy checking, proposal generation, AMS updates and more. We maintain a SOC 2 framework guaranteeing specific protections.

AICPA SOC certification sealApplied Certified Vendor Integration badge

How we protect you

Built for sensitive work
from day one.

Data safeguards

Your data is continuously protected against unauthorized access and security breaches.

No data training

We never train our AI models using your proprietary data.

Data residency

All customer data and records are housed and secured in the U.S.

System stability

We monitor infrastructure to prevent downtime, ensuring systems are available when you need them.

FAQs

  • Where is data stored, and who can access it?

    Data is hosted in the United States on SOC 2-audited infrastructure. Access is gated by role-based controls; every read or write is timestamped and logged in an immutable audit trail.

  • Do you use my data to train AI models?

    As part of our SOC 2 certification, we never use your data to train our models.

  • How are accounts and permissions controlled?

    Role-based access controls let you grant permissions down to the account, line, and field level. Your team sees only what they need to.

  • What happens when a record is updated or deleted?

    Every change is timestamped and logged in an immutable audit trail, so you always have a complete, exportable history of who did what and when.

  • Can I get a BAA or copies of the audit reports?

    Yes. We provide a signed BAA for HIPAA-covered workflows, and SOC 2 Type II and ISO 27001 reports are available under NDA.

  • Who do I contact about a security issue?

    Reach our security team directly at security@coverflow.com. We acknowledge every report and respond on a defined timeline.

Grow your book
with Coverflow.

Book a demo