Skip to content

Security

Insurance data is sensitive by default.

We built Evrment knowing what an insurance agency actually holds: health, identity, financial and policy information, and private communications. Security cannot be an add-on when that is the payload. Here is what protects it today, and what is still required before general availability.

Security at a glance

Evrment is in daily use by its founding agency today. The hosted service for other agencies at evrment.ai is being prepared now, and several controls are required before it opens. We would rather show you that list than round it up.

We will not put a badge on this page before an independent party has signed the report behind it.

  • HTTPS / TLSIn place
  • Encryption at restIn place
  • AES-256-GCM credential vaultIn place
  • Workspace and role isolationIn progress
  • Audit trailIn place
  • DNC and communication controlsIn place
  • Recording consentIn place
  • AI workspace boundariesIn place

Sensitive data belongs in protected fields.

Not in arbitrary text boxes. An SSN belongs in a masked, encrypted field with an audited reveal, never in notes. Health details belong in the underwriting data area, never in team chat. Bank details belong in a protected workflow, never in a text message.

Most of this protected domain is still being built, and the statuses say so. Until it ships, sensitive identifiers, account numbers and detailed health information stay out of every unstructured field.

  • HealthProtected storage · restricted access · auditable accessMedical history, prescriptions, underwriting answersRequired before GA
  • IdentityMasked · encrypted · controlled revealSSN, date of birth, address, licence informationRequired before GA
  • FinancialRestricted · encrypted · auditedBank details, commission informationRequired before GA
  • PolicyWorkspace-scoped · permissioned · traceableApplications, coverage, beneficiary informationIn progress
  • CommunicationsConsent-aware · access-controlled · retention-awareCalls, messages, recordingsRequired before GA

Generic architecture was not designed around the insurance data lifecycle.

Evrment is. Where that is still the design target rather than the product, the row says so.

Generic CRM architecture compared with Evrment, with current status
Generic architectureEvrmentToday
A notes fieldA purpose-built protected data domainDesign target; the protected domain has not shipped.Required before GA
One permission modelField- and workflow-sensitive permissionsRoles are enforced today; field-level permissions are the design target.Required before GA
Activity historyHuman, AI and system provenanceEvery change records its actor type, module, action and diff.In place
AI sees it because the user canAI data access is explicitly governedNo model provider is connected; the governing boundary is a requirement.Required before GA
Compliance documented in a handbookCompliance controls in the execution pathDo-not-call, quiet hours and recording consent run in code.In place

How Evrment protects the business

Data protection

HTTPS everywhere, a database encrypted at rest, and carrier logins sealed with AES-256-GCM envelope encryption.

Access & isolation

Individual accounts, roles checked on the server, and AI units confined to your workspace and downline. Multi-agency isolation is in progress.

Audit & accountability

Every human, AI and system action is recorded with its actor, module, action, subject and diff, and exports to CSV.

Compliance guardrails

Your internal do-not-call list on every outbound path, quiet hours for automation, and recording that stays off until you turn it on.

Trust & assurance

Backups, the providers we rely on, what we do and do not claim, your data rights, and how to report an issue.

Certifications

Evrment does not hold a SOC 2 report, ISO 27001 certification, or PCI DSS attestation, and is not a HIPAA business associate. We will not describe the product as having any of them until an independent party has confirmed it. An independent security assessment is planned.

Current

Independent penetration / security assessment
Planned

Roadmap

SOC 2 Type II
Roadmap
ISO/IEC 27001
Under evaluation

Not currently claimed

HIPAA business associate program
Not offered today. HIPAA-regulated workflow support is required before general availability.

Not applicable

PCI DSS
Not applicable — card data is tokenized outside Evrment. Evrment never stores card numbers, CVV, PIN or track data.

Governance is a scale problem before it is a security problem.

One producer governs their own work by remembering. An agency with a hundred producers has more people, more records, more interactions and more permissions to govern than any one person can hold, and the exposure grows with each of them. That is why role-based access, consent records, the audit trail and the autonomy ladder are part of the product rather than a policy document — and why every control on this page states what is actually in place today, and what is not.

Be there when Evrment goes live.

Join the waitlist for early access, launch updates and founding-user benefits. No spam, and you can leave any time.