Security and data

Security, compliance, and who owns the data.

The short version: your data remains yours, and BindIQ is being designed around attributable activity, consent history, and practical portability. Current control availability is shared during diligence.

Data portability

Your data belongs to your agency

The book you built is yours. BindIQ's product direction is to process it only to provide the platform to your agency.

Portability is part of the design: agencies should be able to leave with their records in a usable format. Confirm current export availability with us during diligence.

Communications

Consent, tracked per contact and channel

The planned consent model records when and how permission was given, per person and per channel, with history attached to the contact. The goal is an attributable record rather than a recollection; confirm current channel support during diligence.

Financial data

Keeping card data out of agency systems

The payment design uses provider-hosted, tokenized flows so raw card data does not need to sit in the agency's systems. Final provider scope and production availability will be documented before payment features launch.

Access and audit

Controls are being designed around the record.

These are product and security design targets under implementation, not a certification or claim that every control is live today.

Planned access controls

Role-based access control
The design assigns access according to each person’s role in the platform.
Permissions inherited through the agency hierarchy
The permission model is designed around network, agency, branch, and producer structure.
Session controls
Planned controls govern sessions according to workspace access rules.

Planned audit trail

Attributable activity history
The platform is designed to associate important actions with the person and time involved.
Quote and coverage documentation
The product direction keeps the work behind a quote or coverage decision with its record.
Record-level history
The planned history view is intended to show changes without reconstructing them from memory.

Planned data handling

Encryption in transit
The security design calls for protecting data as it moves between the browser and platform.
Encryption at rest
The security design calls for protecting stored platform data.
Per-agency data separation
The data model is intended to keep each agency’s records separated.
Export on request
Data portability is a product commitment; confirm current export availability during diligence.
Security and data

What we have not done yet

BindIQ is early. Formal certification programs take time and cost money, and claiming one before it exists would be the exact kind of thing this page is meant to rule out.

We will name certifications here when they are real and not before. If you need something specific for your own diligence, ask and we will tell you plainly where we are.

Questions we did not answer here?

Ask directly. We would rather have the conversation than write around it.

Request a demo