Your data doesn't leave. Your clients stay protected.
Coverflow safely handles highly sensitive insurance data including policy checking, proposal generation, AMS updates and more. We maintain a SOC 2 framework guaranteeing specific protections.


Built for sensitive work from day one.

Data safeguards
Your data is continuously protected against unauthorized access and security breaches.

No data training
We never train our AI models using your proprietary data.

Data residency
All customer data and records are housed and secured in the U.S.

System stability
We monitor infrastructure to prevent downtime, ensuring systems are available when you need them.
FAQs
Where is data stored, and who can access it?
Data is hosted in the United States on SOC 2-audited infrastructure. Access is gated by role-based controls; every read or write is timestamped and logged in an immutable audit trail.
Do you use my data to train AI models?
As part of our SOC 2 certification, we never use your data to train our models.
How are accounts and permissions controlled?
Role-based access controls let you grant permissions down to the account, line, and field level. Your team sees only what they need to.
What happens when a record is updated or deleted?
Every change is timestamped and logged in an immutable audit trail, so you always have a complete, exportable history of who did what and when.
Can I get a BAA or copies of the audit reports?
Yes. We provide a signed BAA for HIPAA-covered workflows, and SOC 2 Type II and ISO 27001 reports are available under NDA.
Who do I contact about a security issue?
Reach our security team directly at security@coverflow.com. We acknowledge every report and respond on a defined timeline.
