SOC 2

Enterprise-grade compliance.

Built on SOC 2 Type II compliant infrastructure. Every vendor independently audited for security, availability, and confidentiality.

What is SOC 2

The gold standard for SaaS security.

SOC 2 is a compliance framework by the AICPA that defines criteria for managing customer data. The benchmark enterprise buyers use to evaluate SaaS vendors.

  • Type II means controls are tested over time — not just documented
  • Independent auditor verifies controls are operating effectively
  • Covers security, availability, processing integrity, confidentiality, privacy
  • Required by most enterprise procurement and compliance teams
SOC 2 Type II
Type I
Controls designed
Point-in-time assessment
Type II ✓
Controls operating effectively
Tested over 6–12 month period
All Insurance Advice vendors maintain Type II
Trust Service Criteria

Five pillars of SOC 2 compliance.

How Insurance Advice's infrastructure addresses each Trust Service Criterion.

Security

TLS 1.3 in transit, AES-256 at rest, tenant isolation, RBAC.

Availability

Managed infrastructure with uptime monitoring and redundancy.

Processing Integrity

Structured JSON schema validation on every output.

Confidentiality

Multi-tenant isolation, zero AI training on customer data.

Privacy

APP-compliant privacy policy, cross-border disclosure documented.

Vendor Compliance

Every vendor audited. Every layer covered.

Every vendor in our stack maintains independently audited SOC 2 certification.

Vendor
Role
Certification
Status
Anthropic
AI analysis engine
SOC 2 Type II
Certified ✓
AWS
Cloud infrastructure
SOC 2 Type II
Certified ✓
Stripe
Payment processing
SOC 2 Type II, PCI DSS
Certified ✓
CloudFront
CDN & edge delivery
SOC 2 Type II
Certified ✓
Resend
Transactional email
SOC 2 Type II
Certified ✓
What this means for you

Security you can point your compliance team to.

Procurement-ready

When your compliance team asks "Is the vendor SOC 2 compliant?" — the answer is yes, at every layer. Documentation available on request.

APRA alignment

SOC 2 compliant infrastructure aligns with APRA CPS 234 information security requirements for regulated insurance entities.

Enterprise-ready

Large brokerages, insurers, and risk management firms can onboard through their standard vendor assessment process.

Contact

AI-powered insurance.
Coming soon.

We're here to answer your questions. We usually reply within one business day.

Prefer email? Write to hello@insuranceadvice.app