trust center
How we handle company AI data.
Encryption, access, retention, and response. Written for teams about to share AI inventory, prompts, and employee exposure signals.
Maintained by the Insurane team · not an independent audit
This is a demonstration build. Affiliation, carrier, and licence details on this page are placeholders and should not be relied on as live credentials.
trust desk · posture
live- Data handling and retentiondocumented
- Security controls and access rulesdocumented
- Incident response runbookdocumented
demo build · the full record is below
Credibility
Signals we show teams before they share AI inventory
Demo placeholders
Backed by
Y Combinator
Cover placed through
A-rated carrier panel
States we sell in
Licensed producer
01 · overview
Posture at a glance
The controls teams ask about first, before they share prompts, logs, or employee exposure signals.
Encryption standard
0-bit
Org data protected in transit and at rest.
Breach notice clock
0h
Target window to notify affected teams in writing.
Deletion SLA
0d
Tenant data removed after a verified delete request.
Access logged
0%
Handler views recorded on the org timeline.
02 · data lifecycle
A dashboard view of the path your data takes
From intake to deletion. Each stage has a named control posture.
Control room · data lifecycle
How company AI data moves through Insurane
Stage detail
Intake
Company contacts, domains, and AI inventory collected for coverage setup.
Control strength
0%
Relative maturity of safeguards on this stage.
03 · privacy
What we keep, and what we refuse to keep
Short commitments for AI inventory data and for the assessment portal.
What we store
- Company contact details needed for cover and follow-up.
- Domains, tools, and workflows you ask us to watch.
- One-way hashes of prompt and workflow signals used only for matching.
What we do not store
- Full prompt logs after fingerprinting completes.
- Full copies of discovered content beyond what incident response needs.
- Uploaded assessment evidence as a lasting archive.
Risk assessment data
- Questionnaire answers are used to score exposure and support follow-up.
- Uploaded files are processed for analysis and are not kept as a lasting record.
- Your browser privacy choice for the assessment portal is stored locally.
04 · security
Controls that sit under the product
Encryption, access, and audit. The layer that has to work every day.
Encryption in transit
Tenant traffic uses modern TLS. Internal services talk over encrypted channels.
Encryption at rest
Stored org and case records are encrypted with managed keys.
Role-scoped access
Handlers only see files assigned to them. Broader access requires lead approval.
Audit trail
Every sensitive look at an org file is logged with who, when, and why.
Admin-visible timeline
Your named admin can see handler activity on your case history.
Least privilege by default
Production access is time-bound and reviewed. Standing broad access is not the norm.
05 · access & retention
Who sees a file, and for how long
01
Who can see your file
Your named response lead, their team lead, and admins you list in writing. No open browsing across the company.
02
Third parties
No third party gets org file access without your written say-so, except where the law requires disclosure.
03
Retention while covered
We keep what we need to monitor, respond, and underwrite. Incident artifacts are trimmed when the case closes.
04
Leaving
Cancel any month. Ask us to delete everything and we complete removal within 30 days, then confirm in writing.
06 · incident response
If we are breached, we hold our own clock
Same urgency we sell you: fast notice, clear facts, board-ready updates.
Notice target
24h
- Affected teams are told within 24 hours of confirmed impact, in writing.
- We share what we know and what we do not know. We do not wait for a perfect picture.
- Containment, customer guidance, and regulator notice follow the same incident response playbook we sell to you.
07 · compliance posture
Underwriting and licensing, stated plainly
These fields are labeled as demonstration details on this build.
Who underwrites cover
Cover is placed with an A-rated carrier panel through a managing agent. Policy funds sit with the carrier, not Insurane.
Where we are regulated
Licensed as an insurance producer in the states we sell in, with a UK appointed representative arrangement for European members.
Licence references
Licence numbers live at the bottom of every policy document. This demonstration build uses placeholder entity names.
Backed by
Y Combinator
Affiliation on this page is part of the demonstration framing, same as carrier and licence placeholders.
08 · contact & rights
Ask us, or request deletion.
If a sentence on this page needed a second read, that is our problem. Security mail gets a person within two working days.
This is a demonstration build. Affiliation, carrier, and licence details on this page are placeholders and should not be relied on as live credentials.