Security

Security practices for commercial insurance data.

Policy records, policyholder PII, ceded reinsurance financials, and FNOL loss data require specific data security controls. Irys is built with encryption, role-based access, immutable audit logging, and US-only data residency as foundational requirements. We document what we have built — we do not claim certifications we have not completed.

Security Controls
TLS 1.3 encryption in transit
Encrypted at-rest storage
Role-based access control
Immutable audit log

Built for regulated industry requirements.

Irys is designed with the security controls appropriate for insurance operations data. We do not claim certification status not yet completed — we describe what we have built.

Compliance note Irys is designed with SOC 2 Type II controls in mind — access control, availability, confidentiality, and audit logging are built to those standards. Irys is not currently SOC 2 audited. Carriers whose procurement process requires an audited report should factor the audit window into their implementation timeline. We are happy to provide our security controls documentation for your security review process.
Encryption

All data in transit is encrypted with TLS 1.3. Policy data, policyholder PII, and reinsurance financials are encrypted at rest. Encryption keys are managed with per-tenant isolation.

Access Controls

Role-based access control with carrier-level isolation. Underwriter, adjuster, finance, and admin roles are configurable. MFA available for all users. API access requires scoped keys.

Audit Log

Every policy change, claim action, user login, and data export generates an immutable audit event. Audit log is queryable and exportable for regulatory review or internal audit.

Data Residency

Standard deployment uses US-only data centres. State-level data residency isolation available on Regional tier for carriers with specific regulatory requirements.

Backup and Recovery

Daily encrypted backups with a 30-day retention window. Point-in-time recovery available within the retention window. RTO and RPO targets documented per service tier.

Monitoring

Real-time infrastructure monitoring with automated alerts. Carrier admins receive notification of unusual access patterns. Security events are logged and investigated.

Security questions and disclosures.

If you have identified a security concern or vulnerability in the Irys platform, contact us directly at [email protected] with subject line "Security Disclosure." We review all reports and respond within 2 business days.