Mandatory multi-factor authentication
Every carrier staff account enrolls an authenticator app. Recovery codes are shown once and are single-use. Password resets keep MFA in place and revoke previous sessions.
SECURITY AND TRUST
Applications carry FEINs, driver licenses, loss runs and bank connections. This page describes the controls that protect them, in the same plain language we use everywhere else.
Every carrier staff account enrolls an authenticator app. Recovery codes are shown once and are single-use. Password resets keep MFA in place and revoke previous sessions.
Carrier staff, broker and applicant access is decided per request from server-side memberships and appointments. A client-supplied carrier or agency identifier never grants access.
HttpOnly, secure, host-only cookies with CSRF tokens and origin checks on every write. Old-origin writes are rejected.
Accounts are created by invitation with single-use, time-limited links. The API runtime cannot grant itself administrator permission.
Every application, case, rating run, quote, policy, document and audit event carries its carrier scope, enforced with scoped queries and foreign keys.
Submitted applications are frozen. Corrections create new audited revisions; signed evidence is never rewritten. Version checks stop silent overwrites.
Retries and duplicate clicks cannot create duplicate submissions, acceptances or quotes.
Undivo runs on its own database, services and credentials. It shares no runtime, session store or database connection with other Wrab Tech products.
Uploads are stored outside public web roots. Every file is malware-scanned before it can be downloaded, approved or counted toward readiness. Scans that cannot run fail closed.
Downloads are authorized per carrier and agency and verified against stored byte hashes.
FEIN is masked in review until explicitly revealed. Driver dates of birth and license numbers are hidden by default in review and excluded from queue listings.
Telematics and bank-connection secrets are encrypted with AES-256-GCM under dedicated keys and are never returned by the API.
Voice requires the applicant’s AI and audio consent plus browser microphone permission. Closing the assistant or leaving the page stops the microphone.
Lisa acts only with the intake session’s permissions. She cannot sign, submit, bind, change rating rules or collect bank credentials, and she never inherits staff access.
Undivo does not store raw audio. Written conversation retention is off unless the applicant separately consents, and then defaults to 90 days with access limited to authorized carrier staff.
Estimates, quotes and approvals follow carrier configuration and separate approver roles. AI explains; people decide.
The website and workspace are served over HTTPS only, and plain HTTP redirects. The website sends HSTS so browsers never fall back to HTTP.
Per-address request limits, bounded concurrency and per-actor limits on sensitive operations such as broker creation and password work.
Every deployment is an immutable release folder. Rolling back is a pointer change, not a rebuild.
Request bodies, bearer URLs, SQL and conversation content are never written to logs.
ASSURANCE
Undivo has not yet completed a SOC 2 examination or a third-party penetration test. We say so plainly rather than implying otherwise with a badge. Both are planned as part of our production hardening, and we share the current state during procurement.
We answer carrier and MGA security questionnaires and can walk your team through the architecture and data flows. Request this through the demo form.
If you believe you have found a security issue, email info@undivo.ai with “Security” in the subject. We acknowledge reports and keep you informed until the issue is resolved.
The public website collects nothing beyond what you type into the demo form. The workspace and intake application carry their own notices, shown before any business or personal information is entered. Website privacy.
NEXT STEP
We would rather answer the hard questions on the first call than on the last one.