Security at InsuriShield.
Life insurance policies and medical records are among the most sensitive documents a client can share. Protecting them is not a feature of our platform — it is the foundation it's built on.
Last updated: June 2026
Encryption everywhere
AES 256-bit encryption for all data at rest across Salesforce, Google Cloud, and AWS. TLS for everything in transit. Industry-standard asymmetric encryption provided by trusted technology partners.
Minimal access, strictly controlled
Role-based access controls limit customer data to just three authorized employees. Two-factor authentication with an authorization token app is required for all internal systems. No contractors or consultants — none — have access to customer data.
Certified infrastructure
Our servers run in data centers holding SOC 1/2/3 and ISO 27001 certifications, with environments that support HIPAA compliance (BAAs available), GDPR, and FedRAMP authorization through our partners.
Deliberate data lifecycle
Documents enter through the customer portal, are digitized by our processing engine, and results are delivered to your platform of choice. Customer PDFs are stored in a single hardened location — and removed from intermediate systems once transfer completes.
Backup & recovery
Automatic daily backups of all data required to power our products and fulfill active service requests, so a service interruption never becomes data loss.
Tested response, trained people
NIST-based incident response protocols with quarterly reviews. Frequent security assessments, code reviews, and vulnerability scans. Ongoing employee security training, with VPN use mandated on any public or unsecured network.
Built on world-class platforms
All company software is built within the Salesforce Platform or hosted on AWS, with storage across Salesforce, Google Cloud Platform, and Google Workspace. Each partner brings its own defense-in-depth: Salesforce's identity and access management with continuous security monitoring, Google's encryption-by-default and identity-aware proxy, and AWS's built-in DDoS protection and network firewalls — backed by physically hardened data centers with biometric entry control, 24/7 surveillance, and redundant power and cooling.
Health information & HIPAA
Our partner environments support HIPAA compliance, including approved Business Associate Agreements. Where engagements involve protected health information, we classify and handle it at our highest sensitivity tier and will execute a BAA with customers who require one.
Questions or disclosures
We welcome security questions from customers and prospective partners, and we take vulnerability reports seriously. Contact us at contact@insurishield.com and we will respond promptly.