Skip to main content

Platform | Data Security

Enterprise-Grade Data Security for Insurance Carriers

SortSpoke provides SOC 2 Type 2 and HIPAA compliant data security.

At SortSpoke, safeguarding our customer's data is the foundation of everything we do. We are focused on maintaining the highest industry standards to protect your data.

  • Enterprise-grade security with SOC 2 Type 2 and HIPAA compliance certifications to protect your sensitive insurance data
  • End-to-end encryption with TLS 1.2+ for data in transit and AES 256 for data at rest ensuring complete protection
  • Flexible data residency options with AWS's world-class security infrastructure for regulatory compliance and peace of mind
warm hero

SortSpoke Compliance Certifications

SortSpoke maintains the highest industry security standards to protect your insurance data:
SortSpoke SOC 2

SOC 2 Type 2

Service Organization Control (SOC) 2 Type 2

SortSpoke HIPAA Compliant

HIPAA Compliant

Health Insurance Portability and Accountability Act (HIPAA) 

SOC 2 Type 2 Compliance

SortSpoke is SOC 2 Type 2 Complaint

Our SOC 2 Type 2 certification demonstrates our ongoing commitment to implementing rigorous controls that protect your sensitive data and ensure the highest standards of security, availability, and confidentiality. Independent auditors test our controls over a 6-12 month period, proving consistent security—not just a point-in-time snapshot.

SortSpoke Achieves SOC 2 Type 2 Compliance

HIPAA Compliance

SortSpoke is HIPAA Complaint

SortSpoke's HIPAA-compliant infrastructure and processes safeguard protected health information (PHI) throughout the document extraction workflow, enabling health insurance carriers to maintain regulatory compliance while accelerating their underwriting operations. We execute Business Associate Agreements and maintain comprehensive audit trails.

SortSpoke Announces HIPAA Compliance Protecting Health Insurance Data
data-extraction-solution-security

What Security Measures Does SortSpoke Provide?

  • Encrypted-in-transit & At-Rest: All customer data is protected by TLS 1.2+ in-transit and by AES 256 encryption at-rest.
  • Automation Failover & Scaling: SortSpoke provides high-availability, backups, and auto-scaling out-of-the-box.
  • Data Residency: We can host your data in your desired region to ensure it remains within a specific country.
  • SOC 2 Type 2 Compliance: SortSpoke maintains Service Organization Control (SOC) 2 Type 2 certification.
  • HIPAA Compliance: Our platform meets all requirements for healthcare information security and privacy.

SortSpoke is Built for Enterprise

34
Encrypted-in-transit & At-Rest

All customer data is protected by TLS 1.2+ in-transit and by AES 256 encryption at-rest.

34
Automation Failover & Scaling

SortSpoke provides high-availability, backups, and auto-scaling out-of-the-box.

34
Data Residency

We can host your data in your desired region to ensure it remains within a specific country.

AWS - A World Leader in Security

SortSpoke Security Infrastructure Partner

Built for Scale

All SortSpoke instances automatically adjust capacity to maintain the best mix of predictability and optimization for your team.

Security Focused

AWS facilities, networks, and server infrastructures are built and managed by world-class security experts.

Certifications

AWS supports multiple security standards to help satisfy the compliance requirements for many global regulatory agencies.

By clicking Download Now you're confirming that you agree with our Privacy Policy.

SORTSPOKE SECURITY OVERVIEW

Understand exactly how SortSpoke keeps your data secure

Download our Security Overview to see how SortSpoke protects your data. Get the details on our SOC 2 Type 2 and HIPAA compliance, encryption standards, and enterprise-grade security infrastructure.

SortSpoke Security Overview Cover (1)

Privacy Policy

Read about our Privacy Policy here

Our comprehensive Privacy Policy outlines exactly how we collect, use, and protect your information, reflecting our dedication to transparency and data stewardship in everything we do.

Featured Security Resources

Read the top security articles from the SortSpoke Blog

SortSpoke Achieves HIPAA Compliance | Protecting Health Insurance Data
Insurance
SortSpoke Achieves HIPAA Compliance | Protecting Health Insurance Data
by SortSpoke
SortSpoke is now HIPAA compliant, ensuring health insurance data is processed with enterprise-grade security and privacy protections. Learn more
Why HIPAA Compliance Matters for Insurance Carriers (and how SortSpoke gets it right)
Insurance
Why HIPAA Compliance Matters for Insurance Carriers (and how SortSpoke gets it right)
by SortSpoke
HIPAA compliance is critical for insurance carriers processing PHI. Here's what to look for in vendors, and how SortSpoke's platform protects data.
SOC 2 Type 2? What Insurance Carriers Need to Know (and how SortSpoke gets it right)
Insurance
SOC 2 Type 2? What Insurance Carriers Need to Know (and how SortSpoke gets it right)
by SortSpoke
SOC 2 Type 2 certification is now critical for insurance vendors. Here's what insurance carriers actually need to evaluate and how SortSpoke gets it right.

FAQ

SortSpoke Security FAQs

Your data security is our priority—here are answers to common questions about how we protect your sensitive information.

 

#5 - SortSpoke (1)

 

How does SortSpoke ensure the security of sensitive insurance data?
We protect your data with enterprise-grade encryption and maintain both SOC 2 Type 2 and HIPAA compliance certifications. All data is encrypted in transit (TLS 1.2+) and at rest (AES 256). Our human-in-the-loop approach adds an additional security layer with comprehensive audit trails tracking every interaction with your submission data.
What's the difference between SOC 2 and HIPAA compliance?

SOC 2 focuses on security, availability, and confidentiality for any type of sensitive data. It's verified through independent audits over 6-12 months.

HIPAA is specific to healthcare data (protected health information/PHI) and is required for health insurance carriers processing medical records, diagnoses, and health information.

SortSpoke maintains both certifications. Learn more about our SOC 2 Type 2 certification and HIPAA compliance.

Do I need HIPAA compliance if I'm a P&C carrier?

Generally no—HIPAA applies primarily to health insurance carriers, health plans, and companies processing protected health information (PHI). However, workers' compensation claims often involve medical records, which may trigger HIPAA requirements.

If you process any health insurance submissions, life insurance applications with medical records, or workers' comp claims with diagnoses and treatment information, HIPAA compliance is critical.

Learn more: Why HIPAA Compliance Matters for Insurance Carriers

Can I see your SOC 2 report?

Yes. We provide our SOC 2 Type 2 audit report to partners and customers under NDA during the procurement process. The report includes detailed information about our security controls, audit findings, and how we address the Trust Service Criteria.

Contact us to request a copy, or learn more about what's in our SOC 2 certification.

What happens to our documents after SortSpoke processes them?

Documents are handled according to your specified retention requirements, and you maintain complete ownership at all times. You can export or delete your information whenever needed. All document access and modifications are logged in our audit trails.

For health insurance carriers, we follow HIPAA data destruction protocols and include these requirements in our Business Associate Agreements.

How does SortSpoke's AI approach differ from other solutions in terms of security?

Our human-in-the-loop AI keeps underwriters involved in the validation process, making every extraction decision traceable and auditable. Unlike black-box AI systems, SortSpoke maintains:

  • Comprehensive audit trails showing who accessed what data and when
  • Role-based access controls ensuring underwriters only see authorized submissions
  • Validation checkpoints where underwriters review and approve AI extractions
  • Data segregation keeping each carrier's data cryptographically isolated

SortSpoke works within your existing security perimeter, reducing implementation risks while maintaining compliance.

Where can I learn more about SortSpoke's security certifications?

We've published detailed pages about our certifications and security practices:

Educational Resources:

You can also download our Security Overview or contact our security team with specific questions.

How often are your security certifications audited?

SOC 2 Type 2: We undergo annual audits with continuous monitoring between cycles. Our certification covers a 6-12 month audit period, demonstrating ongoing compliance—not just a point-in-time snapshot.

HIPAA: We maintain continuous compliance through regular risk assessments, policy updates, and workforce training. Our controls are reviewed annually as part of our security program.

When regulatory requirements change or new threats emerge, we update our controls immediately—audits simply confirm these practices are working as intended.

Where is our data stored? Can we choose the region?

Yes. SortSpoke offers flexible data residency options through AWS infrastructure. We can host your data in your desired region to ensure it remains within a specific country for regulatory compliance.

Common regions include:

  • United States (multiple AWS regions)
  • Canada
  • European Union

Our infrastructure includes:

  • Redundant storage across multiple availability zones
  • Automated backups and disaster recovery
  • 99.9% uptime SLA with automatic failover

Contact us to discuss your data residency requirements.

BOOK A DEMO NOW

Ready to Move Forward with Confidence?

If you have questions about our security posture or want to discuss how SortSpoke's compliance framework fits your organization's requirements, let's talk.