Security

Built for carrier-grade data requirements

Loss data is sensitive. HyperCal is architected so your data is isolated, encrypted, and accessible only to the identities you control.

AES-256
Encryption at rest
TLS 1.3
Encryption in transit
RBAC
Role-based access
Isolated
Per-tenant storage
Security pillars

Three layers of protection

Data Encryption

All data encrypted at rest with AES-256 using per-tenant keys. All data in transit encrypted with TLS 1.3. Keys managed separately from data storage.

Access Control

Role-based access control with fine-grained permissions per LOB and function. SAML and OIDC SSO supported. Multi-factor authentication enforced for all user accounts.

Tenant Isolation

Each carrier's data resides in isolated storage with no shared compute paths. Logical and physical separation between tenant environments at the storage and processing layer.

Controls

What we enforce by default

Per-tenant encryption keys

Separate encryption keys per carrier. Key rotation on configurable schedule without service interruption.

Multi-factor authentication

MFA enforced for all platform users. Authenticator app and hardware key options supported.

Activity logging

All user actions logged with identity, timestamp, and affected resource. Logs retained for a minimum of 7 years and exportable on demand.

Network segmentation

Processing and storage networks segmented. Inbound access restricted to authenticated API surfaces only.

Automated backups

Hourly incremental backups with point-in-time recovery. Backup storage geographically separated from primary.

Penetration testing

Third-party penetration testing performed annually. Findings and remediation timelines shared with carriers on request.

Data handling

How your loss data is handled

Data residency

Data stored in the region you select at onboarding. No cross-region replication without explicit carrier consent.

No training use

Your loss data is never used to train models for other carriers or any external purpose. Contractually prohibited.

Data processing agreement

Full DPA available at contract execution. Covers sub-processors, retention periods, and deletion procedures.

Deletion on request

Complete data deletion within 30 days of contract termination. Deletion certificates provided for all storage including backups.

Security review

Request our security documentation

We provide a full security information package including architecture overview, penetration test summary, and data processing agreement to carriers in our access program.