SECURITY AND TRUST

Access is decided on the server. Records cannot be quietly rewritten.

Applications carry FEINs, driver licenses, loss runs and bank connections. This page describes the controls that protect them, in the same plain language we use everywhere else.

Identity and access

Mandatory multi-factor authentication

Every carrier staff account enrolls an authenticator app. Recovery codes are shown once and are single-use. Password resets keep MFA in place and revoke previous sessions.

Role and scope enforced on the server

Carrier staff, broker and applicant access is decided per request from server-side memberships and appointments. A client-supplied carrier or agency identifier never grants access.

Session and request protection

HttpOnly, secure, host-only cookies with CSRF tokens and origin checks on every write. Old-origin writes are rejected.

Operator-issued invitations

Accounts are created by invitation with single-use, time-limited links. The API runtime cannot grant itself administrator permission.

Data isolation and integrity

Carrier-scoped records

Every application, case, rating run, quote, policy, document and audit event carries its carrier scope, enforced with scoped queries and foreign keys.

Immutable submissions

Submitted applications are frozen. Corrections create new audited revisions; signed evidence is never rewritten. Version checks stop silent overwrites.

Idempotent writes

Retries and duplicate clicks cannot create duplicate submissions, acceptances or quotes.

Independent database and runtime

Undivo runs on its own database, services and credentials. It shares no runtime, session store or database connection with other Wrab Tech products.

Documents and sensitive fields

Private document storage

Uploads are stored outside public web roots. Every file is malware-scanned before it can be downloaded, approved or counted toward readiness. Scans that cannot run fail closed.

Authorized downloads with integrity checks

Downloads are authorized per carrier and agency and verified against stored byte hashes.

Masked by default

FEIN is masked in review until explicitly revealed. Driver dates of birth and license numbers are hidden by default in review and excluded from queue listings.

Encrypted credentials

Telematics and bank-connection secrets are encrypted with AES-256-GCM under dedicated keys and are never returned by the API.

AI and voice

Explicit consent

Voice requires the applicant’s AI and audio consent plus browser microphone permission. Closing the assistant or leaving the page stops the microphone.

Bounded authority

Lisa acts only with the intake session’s permissions. She cannot sign, submit, bind, change rating rules or collect bank credentials, and she never inherits staff access.

No audio retention by Undivo

Undivo does not store raw audio. Written conversation retention is off unless the applicant separately consents, and then defaults to 90 days with access limited to authorized carrier staff.

Human review by design

Estimates, quotes and approvals follow carrier configuration and separate approver roles. AI explains; people decide.

Operations

TLS everywhere

The website and workspace are served over HTTPS only, and plain HTTP redirects. The website sends HSTS so browsers never fall back to HTTP.

Rate limiting and admission control

Per-address request limits, bounded concurrency and per-actor limits on sensitive operations such as broker creation and password work.

Versioned releases with rollback

Every deployment is an immutable release folder. Rolling back is a pointer change, not a rebuild.

Minimal logging

Request bodies, bearer URLs, SQL and conversation content are never written to logs.

ASSURANCE

What we have done, and what we have not done yet.

Independent audits

Undivo has not yet completed a SOC 2 examination or a third-party penetration test. We say so plainly rather than implying otherwise with a badge. Both are planned as part of our production hardening, and we share the current state during procurement.

Security questionnaires

We answer carrier and MGA security questionnaires and can walk your team through the architecture and data flows. Request this through the demo form.

Vulnerability reports

If you believe you have found a security issue, email info@undivo.ai with “Security” in the subject. We acknowledge reports and keep you informed until the issue is resolved.

Data and privacy

The public website collects nothing beyond what you type into the demo form. The workspace and intake application carry their own notices, shown before any business or personal information is entered. Website privacy.

Request the security overview

NEXT STEP

Bring your security team to the walkthrough.

We would rather answer the hard questions on the first call than on the last one.

Get a demo