Back to RiskSurvey.ai

Trust & Security

Carriers hold sensitive policyholder data to the highest standard. So do we. RiskSurvey.ai is built with SOC 2-aligned controls by design — and audit-committed by contract.

Encryption Everywhere

All data is encrypted in transit (TLS 1.2+) and at rest. Policyholder data, photos, and reports are never stored or transmitted unencrypted.

Carrier Data Isolation

Strict multi-tenant architecture — every query is scoped to your carrier. Your data is never visible to, or commingled with, any other carrier on the platform.

MFA & Role-Based Access

Multi-factor authentication for staff accounts, granular role-based permissions (admin, underwriter, loss control, broker), and row-level security for field staff.

Comprehensive Audit Logging

Every data access, report action, recommendation closure, and configuration change is logged with actor, timestamp, and IP — reviewable at any time.

Monitored Infrastructure

Real-time error monitoring, deep health checks with database connectivity verification, and uptime alerting on our production environment.

Your Data Stays Yours

Carrier data is never used to train public AI models. Configurable retention, full export, and deletion on offboarding — backed by contractual data processing terms.

Compliance Roadmap

Our security program is aligned to the SOC 2 Trust Services Criteria today, with written information security, access control, and incident response policies in force. We contractually commit to completing a SOC 2 Type I examination in our master service agreements, and we respond to carrier security questionnaires (SIG Lite / CAIQ) within two business days.

Security questions or vendor review requests: security@risksurvey.ai