Security

Built to be trusted
with your book.

Brokers, lenders and owners put their policy data, pricing and portfolio exposure on Advocate. We protect it with layers of independently audited controls, encryption wherever data moves or rests, and a security program certified to ISO/IEC 27001:2022.

Guiding principle

Defense in depth.

Independent, audited layers of protection from people to data, so no single control has to hold on its own. Customer data is encrypted in transit and at rest, production access needs multi-factor authentication over encrypted connections, and every layer is published as controls in our Trust Center.

  1. Data

    Encrypted in transit and at rest, classified and retained by policy.

  2. Application

    Penetration-tested annually, monitored and patched continuously.

  3. Infrastructure

    Segmented networks, MFA-gated access, intrusion detection.

  4. Organization

    Vetted people, reviewed policies, independently audited controls.

Certifications and controls

Audited by outsiders, not just by us.

Independent auditors examine how our security program is designed and whether it operates as described. The controls they test are grouped into five areas and published, with their current status, in the Trust Center.

  • Certified

    ISO/IEC 27001:2022

    Our information security management system is certified against the 2022 revision of ISO/IEC 27001 by an accredited external auditor. The certificate and audit report are available on request.

  • Report available

    SOC 2 Type II

    An independent auditor examined the design and operating effectiveness of our controls against the AICPA Trust Services Criteria for Security across an observation period, not at a single point in time.

  • Maintained

    Cyber insurance

    We carry technology and cyber insurance to limit the financial impact of a security incident or business disruption. The policy summary is available on request.

70+ controls across five areas

Browse every control
  • Infrastructure security

    Restricted, MFA-protected production access, and segmented networks under continuous monitoring.

  • Product security

    Encryption in transit and at rest, annual penetration testing, and formal vulnerability management.

  • Data and privacy

    Data classification, retention and disposal procedures, and deletion when a customer leaves.

  • Organizational security

    Background checks, security training, confidentiality agreements, and centrally managed devices.

  • Internal security procedures

    Change management, quarterly access reviews, tested incident response and recovery plans, and vendor oversight.

Enterprise ready

The controls your security team will ask about.

Identity, isolation, logging and the data lifecycle, answered up front. Anything not covered here is usually in our Trust Center, and our team will complete your security questionnaire.

  • Single sign-on

    SAML 2.0 and OIDC with the identity provider you already run, including Okta, Microsoft Entra ID and Google Workspace.

  • Multi-factor authentication

    Available to every user, and organization admins can require it for their whole team. Access to our own production systems always requires it.

  • Role-based access

    Predefined roles scope what each person can see and do, with deny-by-default permissions and least privilege throughout.

  • Tenant isolation

    Every record is scoped to your organization and every query is filtered by it in the application layer, so no customer can reach another customer’s data.

  • Activity history

    Sign-ins, changes and access to records are logged in an activity history for your organization. Export to your SIEM is on our roadmap.

  • Encryption everywhere

    TLS 1.3 protects data in transit. Datastores holding customer data are encrypted at rest with industry-standard encryption, and key access is restricted to the few who need it.

  • Your data, your terms

    You own your data. On termination we return or delete it within 30 days by hard deletion, and backups age out on a fixed rotation.

  • Built to stay up

    Hosted on Amazon Web Services with encrypted, restore-tested backups and a business continuity plan we test every year.

  • Tested continuously

    Automated penetration testing runs continuously, with periodic manual tests by an independent third party and quarterly vulnerability scans of external-facing systems.

AI you can audit

Your data works for you.
It never trains a model.

AI in Advocate reads insurance documents and extracts what matters, with citations back to the source. The Responsible AI Use Policy that governs it comes down to six commitments.

Input
Your documents, treated as Confidential
Model
Zero retention, no training
Output
Cited fields, reviewed by people
  1. 01

    No training on your data

    We do not train or fine-tune models on customer data, and we do not train foundation models at all. Market benchmarks are built from aggregated, de-identified data, as our DPA describes.

  2. 02

    Zero retention at model providers

    Inference runs with frontier model providers such as Anthropic and OpenAI under enterprise agreements configured for zero data retention. Prompts and outputs are not stored by the provider beyond the request.

  3. 03

    People make the call

    AI extracts and classifies against source documents and cites them. Compliance determinations run through deterministic rules, and outputs are treated as preliminary until a person has reviewed them.

  4. 04

    Every interaction is logged

    Prompts and responses are recorded in an audit log under the same access controls as the rest of the platform, so any AI interaction can be traced.

  5. 05

    Minimal data, least privilege

    AI features process only the data a task needs, behind role-based access and MFA-protected production systems, and every AI system we run is inventoried and classified.

  6. 06

    Governed, tested, in scope

    Vendors are assessed for SOC 2 and no-training commitments, model changes are validated and announced in product releases, and AI functionality sits within our SOC 2 scope. An AI System Card is available on request.

Vulnerability disclosure

Found something? Tell us first.

We run a vulnerability disclosure program with rewards for qualifying reports and a safe harbor for good-faith research. Write to us, or read the full program for scope and rules.

  1. 01

    Report

    Email security@tryadvocate.com with a summary, reproduction steps, your environment and any proof of concept.

  2. 02

    Triage

    We confirm receipt, reproduce the issue and assess its severity and real-world impact.

  3. 03

    Remediate

    We fix the issue and keep you informed along the way. We may come back with questions.

  4. 04

    Disclose

    Once resolved, we update affected customers where warranted and settle any reward.

FAQ

Security questions, answered

Is customer data encrypted?

Yes. Data is encrypted in transit whenever it travels over public networks, and the datastores that hold customer data are encrypted at rest.

Do you use our data to train AI models?

No. We do not train or fine-tune models on customer data. Model providers process prompts under zero data retention terms, and market benchmarks are built only from aggregated, de-identified data as described in our Data Protection Addendum.

Do you support single sign-on and MFA?

Yes. SAML 2.0 and OIDC single sign-on works with identity providers such as Okta, Microsoft Entra ID and Google Workspace. Multi-factor authentication is available to every user and organization admins can require it.

Can I get your SOC 2 report or ISO 27001 certificate?

Yes. Request them through our Trust Center. Approved requesters can download the SOC 2 Type II report, the ISO/IEC 27001:2022 certificate and audit report, and our cyber insurance policy summary.

Show 4 more questions
Where does Advocate run?

Our cloud infrastructure runs on Amazon Web Services, with supporting services on Google Cloud and MongoDB Atlas as a database service. The full list of subprocessors is published in our Data Protection Addendum.

How do you vet vendors?

Critical vendors are inventoried, held to our security and privacy requirements through written agreements, and reviewed at least annually under our vendor management program.

How do I report a security vulnerability?

Email security@tryadvocate.com with a summary, reproduction steps and details of your environment. Our vulnerability disclosure program explains scope, rewards and the safe harbor we extend to good-faith researchers.

Do you carry cyber insurance?

Yes. We maintain technology and cyber insurance to limit the financial impact of business disruption. The policy summary is available on request through the Trust Center.

Trust, documented.

Certificates, reports, subprocessors and every control, in one place.