Guiding principle
Defense in depth.
Independent, audited layers of protection from people to data, so no single control has to hold on its own. Customer data is encrypted in transit and at rest, production access needs multi-factor authentication over encrypted connections, and every layer is published as controls in our Trust Center.
Data
Encrypted in transit and at rest, classified and retained by policy.
Application
Penetration-tested annually, monitored and patched continuously.
Infrastructure
Segmented networks, MFA-gated access, intrusion detection.
Organization
Vetted people, reviewed policies, independently audited controls.
Certifications and controls
Audited by outsiders, not just by us.
Independent auditors examine how our security program is designed and whether it operates as described. The controls they test are grouped into five areas and published, with their current status, in the Trust Center.
- Certified
ISO/IEC 27001:2022
Our information security management system is certified against the 2022 revision of ISO/IEC 27001 by an accredited external auditor. The certificate and audit report are available on request.
- Report available
SOC 2 Type II
An independent auditor examined the design and operating effectiveness of our controls against the AICPA Trust Services Criteria for Security across an observation period, not at a single point in time.
- Maintained
Cyber insurance
We carry technology and cyber insurance to limit the financial impact of a security incident or business disruption. The policy summary is available on request.
70+ controls across five areas
Browse every controlInfrastructure security
Restricted, MFA-protected production access, and segmented networks under continuous monitoring.
Product security
Encryption in transit and at rest, annual penetration testing, and formal vulnerability management.
Data and privacy
Data classification, retention and disposal procedures, and deletion when a customer leaves.
Organizational security
Background checks, security training, confidentiality agreements, and centrally managed devices.
Internal security procedures
Change management, quarterly access reviews, tested incident response and recovery plans, and vendor oversight.
Enterprise ready
The controls your security team will ask about.
Identity, isolation, logging and the data lifecycle, answered up front. Anything not covered here is usually in our Trust Center, and our team will complete your security questionnaire.
Single sign-on
SAML 2.0 and OIDC with the identity provider you already run, including Okta, Microsoft Entra ID and Google Workspace.
Multi-factor authentication
Available to every user, and organization admins can require it for their whole team. Access to our own production systems always requires it.
Role-based access
Predefined roles scope what each person can see and do, with deny-by-default permissions and least privilege throughout.
Tenant isolation
Every record is scoped to your organization and every query is filtered by it in the application layer, so no customer can reach another customer’s data.
Activity history
Sign-ins, changes and access to records are logged in an activity history for your organization. Export to your SIEM is on our roadmap.
Encryption everywhere
TLS 1.3 protects data in transit. Datastores holding customer data are encrypted at rest with industry-standard encryption, and key access is restricted to the few who need it.
Your data, your terms
You own your data. On termination we return or delete it within 30 days by hard deletion, and backups age out on a fixed rotation.
Built to stay up
Hosted on Amazon Web Services with encrypted, restore-tested backups and a business continuity plan we test every year.
Tested continuously
Automated penetration testing runs continuously, with periodic manual tests by an independent third party and quarterly vulnerability scans of external-facing systems.
AI you can audit
Your data works for you.
It never trains a model.
AI in Advocate reads insurance documents and extracts what matters, with citations back to the source. The Responsible AI Use Policy that governs it comes down to six commitments.
- Input
- Your documents, treated as Confidential
- Model
- Zero retention, no training
- Output
- Cited fields, reviewed by people
- 01
No training on your data
We do not train or fine-tune models on customer data, and we do not train foundation models at all. Market benchmarks are built from aggregated, de-identified data, as our DPA describes.
- 02
Zero retention at model providers
Inference runs with frontier model providers such as Anthropic and OpenAI under enterprise agreements configured for zero data retention. Prompts and outputs are not stored by the provider beyond the request.
- 03
People make the call
AI extracts and classifies against source documents and cites them. Compliance determinations run through deterministic rules, and outputs are treated as preliminary until a person has reviewed them.
- 04
Every interaction is logged
Prompts and responses are recorded in an audit log under the same access controls as the rest of the platform, so any AI interaction can be traced.
- 05
Minimal data, least privilege
AI features process only the data a task needs, behind role-based access and MFA-protected production systems, and every AI system we run is inventoried and classified.
- 06
Governed, tested, in scope
Vendors are assessed for SOC 2 and no-training commitments, model changes are validated and announced in product releases, and AI functionality sits within our SOC 2 scope. An AI System Card is available on request.
Vulnerability disclosure
Found something? Tell us first.
We run a vulnerability disclosure program with rewards for qualifying reports and a safe harbor for good-faith research. Write to us, or read the full program for scope and rules.
- 01
Report
Email security@tryadvocate.com with a summary, reproduction steps, your environment and any proof of concept.
- 02
Triage
We confirm receipt, reproduce the issue and assess its severity and real-world impact.
- 03
Remediate
We fix the issue and keep you informed along the way. We may come back with questions.
- 04
Disclose
Once resolved, we update affected customers where warranted and settle any reward.
FAQ
Security questions, answered
Is customer data encrypted?
Yes. Data is encrypted in transit whenever it travels over public networks, and the datastores that hold customer data are encrypted at rest.
Do you use our data to train AI models?
No. We do not train or fine-tune models on customer data. Model providers process prompts under zero data retention terms, and market benchmarks are built only from aggregated, de-identified data as described in our Data Protection Addendum.
Do you support single sign-on and MFA?
Yes. SAML 2.0 and OIDC single sign-on works with identity providers such as Okta, Microsoft Entra ID and Google Workspace. Multi-factor authentication is available to every user and organization admins can require it.
Can I get your SOC 2 report or ISO 27001 certificate?
Yes. Request them through our Trust Center. Approved requesters can download the SOC 2 Type II report, the ISO/IEC 27001:2022 certificate and audit report, and our cyber insurance policy summary.
Show 4 more questionsShow fewer questions
Where does Advocate run?
Our cloud infrastructure runs on Amazon Web Services, with supporting services on Google Cloud and MongoDB Atlas as a database service. The full list of subprocessors is published in our Data Protection Addendum.
How do you vet vendors?
Critical vendors are inventoried, held to our security and privacy requirements through written agreements, and reviewed at least annually under our vendor management program.
How do I report a security vulnerability?
Email security@tryadvocate.com with a summary, reproduction steps and details of your environment. Our vulnerability disclosure program explains scope, rewards and the safe harbor we extend to good-faith researchers.
Do you carry cyber insurance?
Yes. We maintain technology and cyber insurance to limit the financial impact of business disruption. The policy summary is available on request through the Trust Center.
Trust, documented.
Certificates, reports, subprocessors and every control, in one place.