Security
We ask businesses whether they have MFA. We had better have it.
IronKey builds to 23 NYCRR 500 as the high-water mark regardless of which state a policy is written in, plus GLBA safeguards, state insurance data security acts, and CCPA/CPRA where it applies.
Payments
Card data never touches IronKey systems. Hosted Checkout and Payment Element only, which keeps us in SAQ-A scope. The voice assistant is hard-blocked from accepting a card number and will interrupt a caller who starts reading one.
Premium trust
Fiduciary separation is enforced in code, not policy: a premium movement that would touch an operating account is rejected before it is written, and trust cash cannot go negative.
Model risk
The assistant is screened on input and on output. It cannot give coverage advice, cannot represent that something is covered, and cannot bind. Prohibited outputs are caught and replaced before they are spoken.
Vendors
An unconfigured vendor is excluded from the fan-out and reported as unconfigured. It never returns a fabricated premium that could become a representation to a customer.
Live integration status in this environment
| System | Status |
|---|---|
| Stripe | unconfigured |
| AMS360 | unconfigured |
| InsureZone (comparative rating hub) | unconfigured |
| First Connect (digital shelf) | unconfigured |
| Amwins Access (wholesale specialty) | unconfigured |
| Coterie (instant small commercial) | unconfigured |
| Swyfft (digital homeowners) | unconfigured |
| U.S. Census Geocoder | live |
| OpenFEMA disaster declarations | live |
| U.S. Census ACS 5-year | unconfigured |
| U.S. Census County Business Patterns | unconfigured |
| Verisk property / A-PLUS / CLUE | unconfigured |
| LexisNexis Risk (MVR, RVP, business) | unconfigured |
| ATTOM parcel and property characteristics | unconfigured |
| CoreLogic property / CAT | unconfigured |
| Milliman analytics | unconfigured |
| CMS / CDC public health files | unconfigured |
Before the first bind
- Third-party penetration test with findings remediated
- Carrier IT security questionnaires completed for every appointment
- Vendor DPAs executed; a BAA wherever protected health information could exist
- Errors-and-omissions cover sized to digital submission volume, not headcount