Skip to main content

Resources | Security Overview

Understand Exactly How SortSpoke Keeps Your Data Secure

When processing sensitive insurance documents, security isn't negotiable. Your customers trust you with their data—and you need partners who take that responsibility as seriously as you do.

Our Security Overview provides transparent details on how SortSpoke protects your data with SOC 2 Type 2 certification, HIPAA compliance, and enterprise-grade security infrastructure built specifically for insurance.

What you'll learn:

  • SOC 2 Type 2 certified with independent audits validating that our security controls operate effectively over time—not just point-in-time design.
  • HIPAA compliant with all required administrative, physical, and technical safeguards. Business Associate Agreements (BAAs) available for all customers processing PHI.
  • Multi-layer encryption using AES-256 for data at rest and TLS 1.2+ for data in transit ensures your documents stay protected.
  • Continuous security monitoring with regular penetration testing and vulnerability assessments to identify and address potential risks.
  • AWS infrastructure leveraging security-focused design, high availability, backups, disaster recovery, and auto-scaling capabilities.
  • Flexible data residency options to help meet your regulatory and contractual requirements.

Download the full Security Overview to dive deeper: 

  • Complete security controls matrix with implementation details
  • SOC 2 Type 2 Trust Services Criteria coverage
  • Encryption, access controls, and authentication protocols
  • Data segregation, backup, and disaster recovery procedures
  • Customer responsibilities in our shared security model

 

Get Your Copy Now

SortSpoke Security Overview Cover (1)

Download our Security Overview to see how SortSpoke protects your data. Get the details on our SOC 2 Type 2 and HIPAA compliance, encryption standards, and enterprise-grade security infrastructure.

By clicking Download Now you're confirming that you agree with our Privacy Policy.

Trusted by innovative insurance carriers, MGAs, and BPOs

  • RGA SortSpoke Logo nbg
  • Sompo Logo SortSpoke nbg
  • Great American Insurance GAIG Logo SortSpoke nbg
  • CannGen logo SortSpoke nbg
  • SCM Insurance Services Logo SortSpoke nbg
  • TAI Logo SortSpoke nbg
  • agile
  • Teranet_logo-SortSpoke-case-study
  • UiPath_2019_Corporate_Logo
  • Pega Logo SortSpoke nbg
  • 133868290
  • logo-bdo
  • burnie-group-logo-2021-stacked
  • 806443562
  • onedigital
  • Exavalu Logo SortSpoke nbg
  • Optalitix Logo SortSpoke nbg
  • Fenris Logo SortSpoke nbg
  • Veridion LogoSortSpoke nbg

Featured Security Resources

Read the top security articles from the SortSpoke Blog

What is a Loss Run Report
Insurance
What is a Loss Run Report
by SortSpoke
Learn what loss run reports are, why they matter in underwriting, and how to process them efficiently. Complete guide on loss run report analysis and automation.
The 90-25 Gap: Why Insurance Leaders Talk About AI But Don't Act
Insurance
The 90-25 Gap: Why Insurance Leaders Talk About AI But Don't Act
by SortSpoke
90% of insurance leaders agree AI-human collaboration is urgent, but only 25% have acted. Learn why this gap exists and how to close it before competitors do.
Deloitte 2026 Global Insurance Outlook AI Trends
Insurance
Deloitte 2026 Global Insurance Outlook AI Trends
by SortSpoke
Deloitte's 2026 Global Insurance Outlook reveals how insurers are moving from AI pilots to production. Discover key insights on human-AI collaboration.

FAQ

SortSpoke Security FAQs

Your data security is our priority—here are answers to common questions about how we protect your sensitive information.

 

#5 - SortSpoke (1)

 

How does SortSpoke ensure the security of sensitive insurance data?
We protect your data with enterprise-grade encryption and maintain both SOC 2 Type 2 and HIPAA compliance certifications. All data is encrypted in transit (TLS 1.2+) and at rest (AES 256). Our human-in-the-loop approach adds an additional security layer with comprehensive audit trails tracking every interaction with your submission data.
What's the difference between SOC 2 and HIPAA compliance?

SOC 2 focuses on security, availability, and confidentiality for any type of sensitive data. It's verified through independent audits over 6-12 months.

HIPAA is specific to healthcare data (protected health information/PHI) and is required for health insurance carriers processing medical records, diagnoses, and health information.

SortSpoke maintains both certifications. Learn more about our SOC 2 Type 2 certification and HIPAA compliance.

Do I need HIPAA compliance if I'm a P&C carrier?

Generally no—HIPAA applies primarily to health insurance carriers, health plans, and companies processing protected health information (PHI). However, workers' compensation claims often involve medical records, which may trigger HIPAA requirements.

If you process any health insurance submissions, life insurance applications with medical records, or workers' comp claims with diagnoses and treatment information, HIPAA compliance is critical.

Learn more: Why HIPAA Compliance Matters for Insurance Carriers

Can I see your SOC 2 report?

Yes. We provide our SOC 2 Type 2 audit report to partners and customers under NDA during the procurement process. The report includes detailed information about our security controls, audit findings, and how we address the Trust Service Criteria.

Contact us to request a copy, or learn more about what's in our SOC 2 certification.

What happens to our documents after SortSpoke processes them?

Documents are handled according to your specified retention requirements, and you maintain complete ownership at all times. You can export or delete your information whenever needed. All document access and modifications are logged in our audit trails.

For health insurance carriers, we follow HIPAA data destruction protocols and include these requirements in our Business Associate Agreements.

How does SortSpoke's AI approach differ from other solutions in terms of security?

Our human-in-the-loop AI keeps underwriters involved in the validation process, making every extraction decision traceable and auditable. Unlike black-box AI systems, SortSpoke maintains:

  • Comprehensive audit trails showing who accessed what data and when
  • Role-based access controls ensuring underwriters only see authorized submissions
  • Validation checkpoints where underwriters review and approve AI extractions
  • Data segregation keeping each carrier's data cryptographically isolated

SortSpoke works within your existing security perimeter, reducing implementation risks while maintaining compliance.

Where can I learn more about SortSpoke's security certifications?

We've published detailed pages about our certifications and security practices:

Educational Resources:

You can also download our Security Overview or contact our security team with specific questions.

How often are your security certifications audited?

SOC 2 Type 2: We undergo annual audits with continuous monitoring between cycles. Our certification covers a 6-12 month audit period, demonstrating ongoing compliance—not just a point-in-time snapshot.

HIPAA: We maintain continuous compliance through regular risk assessments, policy updates, and workforce training. Our controls are reviewed annually as part of our security program.

When regulatory requirements change or new threats emerge, we update our controls immediately—audits simply confirm these practices are working as intended.

Where is our data stored? Can we choose the region?

Yes. SortSpoke offers flexible data residency options through AWS infrastructure. We can host your data in your desired region to ensure it remains within a specific country for regulatory compliance.

Common regions include:

  • United States (multiple AWS regions)
  • Canada
  • European Union

Our infrastructure includes:

  • Redundant storage across multiple availability zones
  • Automated backups and disaster recovery
  • 99.9% uptime SLA with automatic failover

Contact us to discuss your data residency requirements.

BOOK A DEMO NOW

Ready to Move Forward with Confidence?

If you have questions about our security posture or want to discuss how SortSpoke's compliance framework fits your organization's requirements, let's talk.