Insurers do not adopt a system they cannot defend to their own information security function. We have been through that review with enterprise customers in Europe and Japan, and the material below reflects what those reviews actually ask for.
Security and compliance
Hosting and data residency
Our platform runs on AWS in the region the customer requires, including in-country deployment with a separate standby region where regulation or procurement demands it. Customer data is separated by tenant. Where a customer requires a dedicated deployment rather than a shared one, that is available as part of an enterprise agreement.
What is processed
An assessment consists of vehicle photographs, the measurements derived from them, and the case metadata the customer chooses to attach. Damage detection itself runs on the device rather than in the cloud. Retention periods are set by the customer, since the claim file, not the vendor, determines how long evidence must be kept.
In our claims integrity product, personal data is removed from material before any analysis is performed.
Application security
The mobile application has been through an independent security assessment, and we maintain that documentation for customer review under NDA. Distribution to enterprise customers is handled through Apple Business Manager as a managed application, with supervised kiosk configuration available where devices are shared between operators, so an assessment device can be restricted to its purpose.
Documentation we provide
- Completed security and privacy questionnaires in the customer's own format.
- Architecture and data flow description covering device, platform and any integration.
- Sub-processor list and hosting region confirmation.
- Application security assessment documentation, under NDA.
- Data processing agreement and, where required, standard contractual clauses.
Vulnerability handling
We respond to customer security enquiries about specific vulnerabilities and third-party components as a matter of routine, including the urgent questionnaires enterprise insurers issue when a component-level vulnerability is published. If you have a security concern about our products, contact us at vitalii.istushkin@soft-edge.com.
Send us your questionnaire.
We would rather answer your security review early than discover it late.