
SOC 2 Type II
Independently attested — report on request.
Encryption
Encrypted in transit and at rest.
Human-in-the-Loop
Human oversight on high-risk decisions.
NAIC AI Model Bulletin
Aligned, Compliance-by-Design.
SECURITY POSTURE
Security controls across every layer
SOC 2 Type II attested — independently examined against the AICPA Trust Services Criteria. Report available on request.
Data Protection & Encryption
Your data is encrypted in transit and at rest. Encryption is enforced on end-user devices alongside mobile device management and anti-malware.
Access Controls
Multi-factor authentication for administrative and critical access, least-privilege permissions, regular access reviews, and enforced onboarding and offboarding.
Monitoring & Incident Response
Audit logs are collected and managed under a documented incident response policy, with an established breach notification process.
Availability & Resilience
Automated backups, a documented business continuity and disaster recovery policy, and an established data recovery process keep your Digital Workforce running.
Confidentiality
Personal Identifying Information is never stored as a reference for LLM training, and data can be removed from storage on request. Your data is yours.
Infrastructure & Change Control
Cloud infrastructure sits behind a Web Application Firewall with restricted production access, automated security scanning, and pull-request-based change control.
AI GOVERNANCE
Secure data and safe AI, together
SOC 2 Type II answers whether your data is safe with us. Human-in-the-Loop oversight and NAIC alignment answer whether the AI is safe in front of your policyholders. Indemn holds both.
Human-in-the-Loop Oversight
A foundational quality-control layer keeps your team in full control. When a situation is high-risk or ambiguous, the AI Associate queues a response for human review, producing a transparent trail of decision-making.
Compliance-by-Design
Deterministic guardrails and moment-by-moment integrity checks keep every Associate aligned with the NAIC AI Model Bulletin. Compliance is built into the architecture, not bolted on afterward.
FRAMEWORK STATUS
Where each program stands today
The Trust Center reflects our current control status at any time.
SOC 2 Type II
Report availableIndependently examined against the AICPA Trust Services Criteria for security, availability, and confidentiality. Report available on request.
GDPR
In progressData-protection program underway. Current status is published on the Trust Center at any time.
HIPAA
In progressSafeguards program underway. Current status is published on the Trust Center at any time.
Need our SOC 2 Type II report?
Request the report or bring your security questionnaire — we will walk your team through our controls and how they map to your requirements.