Where does our claims data live, and who can touch it?

In an enterprise-grade Microsoft Azure environment in the United States, isolated per customer, encrypted in transit and at rest, with no public database port. Claim files contain policyholders' homes, finances, and worst weeks. That's among the most sensitive data a carrier holds. This page is the public summary of how we treat it; the detailed architecture and agreements are available under NDA.

Hosting
ClaimVision runs in an enterprise-grade Microsoft Azure environment, in US regions. We state the hosting platform because it's a trust signal your team can verify. We stop there, because infrastructure detail beyond that belongs in the NDA conversation, not on a web page.
Where your data lives
Claim data is stored and processed only in Microsoft Azure, in regions in the United States. The contracting entity, Decision Agency OÜ, is registered in Estonia, in the EU, so GDPR applies to us as well as to you.
SOC 2 status
ClaimVision runs on Microsoft Azure and is built to SOC 2 principles. We are working towards a SOC 2 Type 2 audit; we are not yet certified, and we'll say so plainly until we are.
Isolation and model training
Each carrier's data is logically isolated: every record belongs to one company, and both the database and the application check it on every request. Your claim data never trains another carrier's models; each carrier's models learn from its own data.
Encryption and access
Data is encrypted in transit (TLS 1.2 or later) and at rest (Azure platform encryption). Users see only their own company's claims. The database has no public port: our engineers reach production only through Azure Bastion, never directly from the internet, and read access to production data needs approval.
The record
The decision history is append-only: recommendations, citations, confidence levels, and human overrides are preserved and never overwritten. This is a security property as much as a compliance one: a record nobody can silently edit is a record everybody can trust. Audit trail →
Retention and return
Your data remains yours. How long it is kept, and how it is archived or deleted when a contract ends, is agreed with each carrier in the contract.
Documentation under NDA
Security architecture detail and data-processing agreements are available to evaluating carriers under NDA. Send your security questionnaire with your first email and we'll work it in parallel with the pilot conversation.

Start the security review now, not after the pilot.