insurane.

we watch · we warn · we pay · we fix it

trust center

How we handle company AI data.

Encryption, access, retention, and response. Written for teams about to share AI inventory, prompts, and employee exposure signals.

Maintained by the Insurane team · not an independent audit

This is a demonstration build. Affiliation, carrier, and licence details on this page are placeholders and should not be relied on as live credentials.

trust desk · posture

live
  • Data handling and retentiondocumented
  • Security controls and access rulesdocumented
  • Incident response runbookdocumented

demo build · the full record is below

Credibility

Signals we show teams before they share AI inventory

Demo placeholders

Backed by

Y Combinator

Cover placed through

A-rated carrier panel

States we sell in

Licensed producer

01 · overview

Posture at a glance

The controls teams ask about first, before they share prompts, logs, or employee exposure signals.

Encryption standard

0-bit

Org data protected in transit and at rest.

Breach notice clock

0h

Target window to notify affected teams in writing.

Deletion SLA

0d

Tenant data removed after a verified delete request.

Access logged

0%

Handler views recorded on the org timeline.

02 · data lifecycle

A dashboard view of the path your data takes

From intake to deletion. Each stage has a named control posture.

Control room · data lifecycle

How company AI data moves through Insurane

Systems nominal

Stage detail

Intake

Company contacts, domains, and AI inventory collected for coverage setup.

Control strength

0%

Relative maturity of safeguards on this stage.

03 · privacy

What we keep, and what we refuse to keep

Short commitments for AI inventory data and for the assessment portal.

What we store

  • Company contact details needed for cover and follow-up.
  • Domains, tools, and workflows you ask us to watch.
  • One-way hashes of prompt and workflow signals used only for matching.

What we do not store

  • Full prompt logs after fingerprinting completes.
  • Full copies of discovered content beyond what incident response needs.
  • Uploaded assessment evidence as a lasting archive.

Risk assessment data

  • Questionnaire answers are used to score exposure and support follow-up.
  • Uploaded files are processed for analysis and are not kept as a lasting record.
  • Your browser privacy choice for the assessment portal is stored locally.

04 · security

Controls that sit under the product

Encryption, access, and audit. The layer that has to work every day.

Encryption in transit

Tenant traffic uses modern TLS. Internal services talk over encrypted channels.

Encryption at rest

Stored org and case records are encrypted with managed keys.

Role-scoped access

Handlers only see files assigned to them. Broader access requires lead approval.

Audit trail

Every sensitive look at an org file is logged with who, when, and why.

Admin-visible timeline

Your named admin can see handler activity on your case history.

Least privilege by default

Production access is time-bound and reviewed. Standing broad access is not the norm.

05 · access & retention

Who sees a file, and for how long

01

Who can see your file

Your named response lead, their team lead, and admins you list in writing. No open browsing across the company.

02

Third parties

No third party gets org file access without your written say-so, except where the law requires disclosure.

03

Retention while covered

We keep what we need to monitor, respond, and underwrite. Incident artifacts are trimmed when the case closes.

04

Leaving

Cancel any month. Ask us to delete everything and we complete removal within 30 days, then confirm in writing.

06 · incident response

If we are breached, we hold our own clock

Same urgency we sell you: fast notice, clear facts, board-ready updates.

Notice target

24h

  • Affected teams are told within 24 hours of confirmed impact, in writing.
  • We share what we know and what we do not know. We do not wait for a perfect picture.
  • Containment, customer guidance, and regulator notice follow the same incident response playbook we sell to you.

07 · compliance posture

Underwriting and licensing, stated plainly

These fields are labeled as demonstration details on this build.

Demo detail

Who underwrites cover

Cover is placed with an A-rated carrier panel through a managing agent. Policy funds sit with the carrier, not Insurane.

Demo detail

Where we are regulated

Licensed as an insurance producer in the states we sell in, with a UK appointed representative arrangement for European members.

Placeholder

Licence references

Licence numbers live at the bottom of every policy document. This demonstration build uses placeholder entity names.

Backed by

Y Combinator

Affiliation on this page is part of the demonstration framing, same as carrier and licence placeholders.

08 · contact & rights

Ask us, or request deletion.

If a sentence on this page needed a second read, that is our problem. Security mail gets a person within two working days.

This is a demonstration build. Affiliation, carrier, and licence details on this page are placeholders and should not be relied on as live credentials.