Security that earns the regulator's trust.
AegisNow is built for the most scrutinized teams in insurance. We protect your data with defense-in-depth controls, prove every AI and human decision with an immutable audit log, and frame our posture honestly — aligned with SOC 2 Type II and ISO 27001, designed for GDPR, with certifications progressing on a published roadmap.
The AegisNow Trust Center is where regulated buyers get their security questions answered before the questionnaire. It documents our controls, certifications, data-privacy posture, and platform-integrity guarantees in one place — including encryption, SSO/SAML, granular RBAC, penetration testing, and a hash-chained WORM audit log that makes every Cortex decision provable. We describe our posture honestly: where a certification is in progress or a framework is “aligned” rather than achieved, we say so.
Compliance, stated plainly.
We map our program to the standards regulated buyers expect — and we never overstate where we are. Each card shows real status, not a logo wall.
SOC 2 Type II
Controls designed against the AICPA Trust Services Criteria (security, availability, confidentiality). Independent Type II examination underway — report available under NDA on request.
ISO/IEC 27001
Our information-security management system is structured around the ISO/IEC 27001 Annex A control families, with formal certification on the compliance roadmap.
GDPR & UK GDPR
Lawful-basis tracking, data-subject request workflows, and EU/UK data-residency options are built into the platform. A Data Processing Addendum (DPA) is available for customers.
Status is illustrative of our security program and roadmap. AegisNow does not claim active certification for any framework marked “in progress” or “aligned.” Current evidence is shared with qualified customers under NDA.
Defense-in-depth, by default.
Layered technical and organizational controls protect data across its lifecycle — so security is the path of least resistance, not an add-on.
Encryption everywhere
Data encrypted in transit with TLS 1.2+ and at rest with AES-256. Key material is managed in a dedicated KMS with scoped, audited access.
SSO / SAML & SCIM
Enterprise single sign-on over SAML 2.0 and OIDC, with SCIM provisioning so joiners, movers, and leavers stay in lockstep with your IdP.
Granular RBAC
Role-based access control down to the module, record, and field level — least-privilege by default, with segregation-of-duties guardrails.
Access governance
MFA enforcement, just-in-time elevation, session controls, and periodic access reviews with attestation captured to the audit trail.
Testing & monitoring
Independent penetration testing on a regular cadence, continuous vulnerability scanning, dependency monitoring, and centralized security logging.
Secure SDLC
Code review, secrets scanning, and SAST/DAST gates in CI; infrastructure-as-code with peer-reviewed change control and immutable deploys.
Your data, your jurisdiction, your rights.
AegisNow is designed for GDPR and UK GDPR from the data model up. You control where regulated data is hosted, how long it is retained, and how data-subject requests are honored — with a DPA and Standard Contractual Clauses backing every engagement.
Regional data residency
Choose where your data lives. EU/UK and US hosting regions keep regulated data within the jurisdiction you operate in.
Data-subject rights
Access, rectification, erasure, and portability requests are supported through structured workflows with defined response SLAs.
Retention & deletion
Configurable retention policies with verifiable deletion on contract end — your data is yours, and we return or destroy it on request.
DPA & SCCs
A Data Processing Addendum incorporating Standard Contractual Clauses governs any cross-border processing on your behalf.
The vendors behind the service.
We keep our subprocessor footprint deliberately small and document it transparently. The categories below are illustrative; the live, named list is provided in your DPA and updated with advance notice of material changes.
| Category | Purpose | Region |
|---|---|---|
| Cloud infrastructure | Application hosting, compute, and managed databases | EU / US (region-selectable) |
| Transactional email | System notifications and account communications | EU / US |
| Product analytics & monitoring | Privacy-preserving usage telemetry and error monitoring | EU / US |
| Customer support tooling | Ticketing and in-app support for your team | EU / US |
Illustrative categories only — not an exhaustive or named list. The authoritative subprocessor register is maintained in your Data Processing Addendum.
Every decision is provable.
Security is not just about keeping intruders out — for regulated AI, it is about proving what happened inside. AegisNow makes the platform itself a source of evidence.
Hash-chained WORM audit log
Every action — human or AI — is written once and never altered. Each entry carries the cryptographic hash of the one before it, so the ledger is tamper-evident: change a single record and the chain breaks visibly. The result is a defensible, reproducible trail your auditors can independently verify.
Cortex AI governance
Cortex, our reasoning copilot, runs inside guardrails: model and prompt versioning, captured sources and rationale, confidence thresholds, and human-in-the-loop checkpoints on consequential decisions. Every output is grounded and logged, so AI assistance never becomes an unaccountable black box.
Reliability you can plan around
We operate with multi-AZ redundancy, automated backups, and a tested disaster-recovery plan. Figures below are illustrative service-level targets — live status is shared with customers.
Questions before the questionnaire.
The answers regulated buyers and their security teams ask most. Need more? Request our full security package.
Pass the security review faster.
Book a demo and we'll walk your team through our controls, share the security package under NDA, and answer your questionnaire in one session.