Security is at Our Core

Layered Protection, Continuous Monitoring and AWS-Powered Resilience

Want to learn more?

Security in Every ISI Deployment

Security is built into every layer of the ISI platform. From infrastructure and application design to daily operational practices, your data, customers, and brand are protected. With AWS-backed architecture and proven safeguards, insurers can grow confidently without adding complexity.

Identity and Access Protection

Control who gets in and what they can access.

  • Single Sign-On (SSO) through Microsoft Entra ID and other identity providers
  • Role-Based Access Control (RBAC) to ensure access rights reflect user responsibilities
  • Multi-factor authentication available for heightened protection

Comprehensive Data Protection

Your data remains encrypted and fully within your control.

  • Encryption in transit using HTTPS/TLS protocol
  • Encryption at rest across databases, file systems, and backups with AWS-managed keys
  • Data residency options to meet regulatory and operational requirements
  • Separation of production, staging, and testing environments to prevent data exposure

Infrastructure-Level Security

Reduce exposure and maintain full visibility across your environment.

  • Only HTTPS (port 443) is accessible externally
  • WS network segmentation to isolate systems and control traffic
  • Continuous monitoring for threats and anomalous activity
  • Logged infrastructure changes to support audit and compliance readiness

Secure, Scalable Growth with AWS

Enterprise-grade security that grows with your business.

  • High availability with redundancy across AWS availability zones
  • Elastic scalability to support peak workloads without disruption or downtime
  • Global access with low latency for internal teams, policyholders, and partners
  • Compliance supported by AWS certifications such as SOC 1/2/3, ISO 27001, GDPR, and PCI DSS
  • No need for hardware or large capital investments

FAQs

  1. How does ISI protect our data throughout the platform?

    ISI protects data through encryption in transit using HTTPS/TLS and encryption at rest across databases, file systems, and backups using AWS-managed keys. Production, staging, and testing environments are separated, and insurer data remains within the insurer’s control.

  2. How can we control who accesses our systems and data?

    The ISI platform supports Single Sign-On through Microsoft Entra ID and other identity providers, role-based access control, and optional multi-factor authentication. Access rights can be configured to reflect user responsibilities and organizational security policies.

  3. How does ISI protect and monitor its cloud infrastructure?

    ISI deployments use AWS-backed infrastructure with network segmentation, restricted external access, continuous monitoring for threats and unusual activity, and logged infrastructure changes. These controls help limit exposure and provide visibility across the environment.

  4. Can ISI support our data residency requirements?

    Yes. ISI provides data residency options to support regulatory and operational requirements.

  5. How does the platform support availability and changing workloads?

    ISI uses redundancy across AWS availability zones to support high availability. Its cloud architecture provides elastic scalability to accommodate peak workloads.

  6. How does ISI support our compliance and governance requirements?

    ISI’s AWS-backed infrastructure supports compliance through AWS certifications and compliance programs, including SOC 1, SOC 2, SOC 3, ISO 27001, PCI DSS, and GDPR. Audit trails and logged events also support regulatory reviews and insurer governance requirements.