Trust & Security

Security that earns the regulator's trust.

AegisNow is built for the most scrutinized teams in insurance. We protect your data with defense-in-depth controls, prove every AI and human decision with an immutable audit log, and frame our posture honestly — aligned with SOC 2 Type II and ISO 27001, designed for GDPR, with certifications progressing on a published roadmap.

Policy & claimssystems of recordExternal signalsbureaus · device · OSINTDocumentsPDFs · forms · mediaData fabricunify · resolve · graphCortexreasoning & decisionsEvidence ledgeraudit · lineage · proof

The AegisNow Trust Center is where regulated buyers get their security questions answered before the questionnaire. It documents our controls, certifications, data-privacy posture, and platform-integrity guarantees in one place — including encryption, SSO/SAML, granular RBAC, penetration testing, and a hash-chained WORM audit log that makes every Cortex decision provable. We describe our posture honestly: where a certification is in progress or a framework is “aligned” rather than achieved, we say so.

Certifications & frameworks

Compliance, stated plainly.

We map our program to the standards regulated buyers expect — and we never overstate where we are. Each card shows real status, not a logo wall.

Audit in progress

SOC 2 Type II

Controls designed against the AICPA Trust Services Criteria (security, availability, confidentiality). Independent Type II examination underway — report available under NDA on request.

Aligned · roadmap

ISO/IEC 27001

Our information-security management system is structured around the ISO/IEC 27001 Annex A control families, with formal certification on the compliance roadmap.

Designed for compliance

GDPR & UK GDPR

Lawful-basis tracking, data-subject request workflows, and EU/UK data-residency options are built into the platform. A Data Processing Addendum (DPA) is available for customers.

Status is illustrative of our security program and roadmap. AegisNow does not claim active certification for any framework marked “in progress” or “aligned.” Current evidence is shared with qualified customers under NDA.

Security controls

Defense-in-depth, by default.

Layered technical and organizational controls protect data across its lifecycle — so security is the path of least resistance, not an add-on.

Encryption everywhere

Data encrypted in transit with TLS 1.2+ and at rest with AES-256. Key material is managed in a dedicated KMS with scoped, audited access.

SSO / SAML & SCIM

Enterprise single sign-on over SAML 2.0 and OIDC, with SCIM provisioning so joiners, movers, and leavers stay in lockstep with your IdP.

Granular RBAC

Role-based access control down to the module, record, and field level — least-privilege by default, with segregation-of-duties guardrails.

Access governance

MFA enforcement, just-in-time elevation, session controls, and periodic access reviews with attestation captured to the audit trail.

Testing & monitoring

Independent penetration testing on a regular cadence, continuous vulnerability scanning, dependency monitoring, and centralized security logging.

Secure SDLC

Code review, secrets scanning, and SAST/DAST gates in CI; infrastructure-as-code with peer-reviewed change control and immutable deploys.

Data privacy & residency

Your data, your jurisdiction, your rights.

AegisNow is designed for GDPR and UK GDPR from the data model up. You control where regulated data is hosted, how long it is retained, and how data-subject requests are honored — with a DPA and Standard Contractual Clauses backing every engagement.

Regional data residency

Choose where your data lives. EU/UK and US hosting regions keep regulated data within the jurisdiction you operate in.

Data-subject rights

Access, rectification, erasure, and portability requests are supported through structured workflows with defined response SLAs.

Retention & deletion

Configurable retention policies with verifiable deletion on contract end — your data is yours, and we return or destroy it on request.

DPA & SCCs

A Data Processing Addendum incorporating Standard Contractual Clauses governs any cross-border processing on your behalf.

Subprocessors

The vendors behind the service.

We keep our subprocessor footprint deliberately small and document it transparently. The categories below are illustrative; the live, named list is provided in your DPA and updated with advance notice of material changes.

CategoryPurposeRegion
Cloud infrastructureApplication hosting, compute, and managed databasesEU / US (region-selectable)
Transactional emailSystem notifications and account communicationsEU / US
Product analytics & monitoringPrivacy-preserving usage telemetry and error monitoringEU / US
Customer support toolingTicketing and in-app support for your teamEU / US

Illustrative categories only — not an exhaustive or named list. The authoritative subprocessor register is maintained in your Data Processing Addendum.

Platform integrity

Every decision is provable.

Security is not just about keeping intruders out — for regulated AI, it is about proving what happened inside. AegisNow makes the platform itself a source of evidence.

Hash-chained WORM audit log

Every action — human or AI — is written once and never altered. Each entry carries the cryptographic hash of the one before it, so the ledger is tamper-evident: change a single record and the chain breaks visibly. The result is a defensible, reproducible trail your auditors can independently verify.

Cortex AI governance

Cortex, our reasoning copilot, runs inside guardrails: model and prompt versioning, captured sources and rationale, confidence thresholds, and human-in-the-loop checkpoints on consequential decisions. Every output is grounded and logged, so AI assistance never becomes an unaccountable black box.

All systems operational

Reliability you can plan around

We operate with multi-AZ redundancy, automated backups, and a tested disaster-recovery plan. Figures below are illustrative service-level targets — live status is shared with customers.

0.0%Uptime target
0mRPO target
0/7Monitoring
Trust FAQ

Questions before the questionnaire.

The answers regulated buyers and their security teams ask most. Need more? Request our full security package.

AegisNow's controls are designed against the AICPA SOC 2 Trust Services Criteria, and an independent SOC 2 Type II examination is in progress. We never claim a certification we do not hold — when the report is issued it will be available to qualified customers and prospects under NDA.

The platform is built for GDPR and UK GDPR compliance, with lawful-basis tracking and data-subject request workflows. You can select EU/UK or US hosting regions so regulated data stays in-jurisdiction, and we sign a Data Processing Addendum incorporating Standard Contractual Clauses for any cross-border processing.

All data is encrypted in transit using TLS 1.2 or higher and at rest using AES-256. Encryption keys are managed in a dedicated key-management service with scoped, fully audited access.

Yes. AegisNow supports enterprise single sign-on over SAML 2.0 and OIDC, plus SCIM provisioning, so user lifecycle and access stay synchronized with your identity provider. MFA can be enforced at the platform level.

Every Cortex action — and every human decision — is written to a hash-chained, write-once (WORM) audit log. Each entry references the cryptographic hash of the prior one, so the record is tamper-evident: any alteration breaks the chain. Combined with model versioning, prompt and source capture, and human-in-the-loop checkpoints, this gives auditors a defensible, reproducible trail.

Independent penetration testing is performed on a regular cadence, alongside continuous vulnerability and dependency scanning. A summary report and remediation status are available to customers under NDA as part of our security review package.

This Trust Center is designed to answer most questions up front. For anything outstanding, request our security package — it includes a completed standard questionnaire (e.g. CAIQ/SIG-style), the DPA, subprocessor list, and audit status. Book a demo and our team will share it under NDA.

Pass the security review faster.

Book a demo and we'll walk your team through our controls, share the security package under NDA, and answer your questionnaire in one session.

Trust Center — Security, Privacy & Compliance | AegisNow | AegisNow Insurance