Security, Privacy
& Trust

Enterprise-Grade Safeguards for Insurers

SigmaSight is SOC 2 Type II audited across the trust principles of security, privacy, and confidentiality.

Enterprise-Grade

Safeguards for Insurers

Independent auditors confirm that our controls operate effectively — ensuring that sensitive claims data is always protected. But for insurers, trust goes further than controls. It also means ensuring fairness in AI and responsible data use at every step.

Enterprise-Grade Safeguards for Insurers

How We Protect Your Data

SOC 2 Type II Certification

Annual independent audits verify that our security, confidentiality, and availability controls operate effectively.

Data Encryption Everywhere

All data is encrypted in transit and at rest.

Secure Hosting & Infrastructure

Built on AWS, leveraging world-class redundancy, disaster recovery, and physical security protections.

Strict Access Controls

Role-based access, least-privilege permissions, continuous monitoring, and logging for all system activity.

Authentication & Identity Management

Multi-factor authentication and SSO (SAML/OAuth) available to align with enterprise identity systems.

Confidentiality by Design

We do not sell, share, or retain carrier data beyond contracted use. Customer data remains private and controlled at all times.

Privacy & Confidentiality

Confidentiality is foundational — protecting our customers, their insureds, and their claims data at every step. We apply the following safeguards:

Zero-Retention Model

Case data is processed only to generate Offer Packages and never retained for unrelated use.

Contractual Protections

Signed Zero Data Retention (ZDR) agreements guarantee that no third-party retains or reuses your data.

Strict Isolation

Each carrier’s data is kept separate; no cross-client commingling or shared training.

Confidential by Design

Services are delivered solely to support your litigation strategy, with strict confidentiality agreements and limited access protocols.

Return or Destruction on Request

Customer data can be securely deleted atany time, or at the end of the engagement.

Return or Destruction on Request

that sensitive legal materials remainprivate, defensible, and fully undercarrier control.

Fairness Without Compromise

We recognize that fairness is a critical concern when applying AI in claims:

Not a Decision Engine Offer Packages assist defense-side negotiation, never replace human judgment

Bias Safeguards — model filters, protected-term scanning, quarterly audits

Auditability — all outputs traceable to underlying evidence

Consistency Across Cases — outputs are evidence-based and subject to human approval

Security and Trust as a Culture

Our commitment goes beyond technology:

Not a Decision Engine Offer Packages assist defense-side negotiation, never replace human judgment

Bias Safeguards model filters, protected-term scanning, quarterly audits

Auditability all outputs traceable to underlying evidence

Compliance

Multiple Resources for Compliance Teams

To support carrier diligence, we provide tailored resources:

Security & Compliance Brief — SOC 2 controls, encryption, and audit scope.

Responsible Data Use in AI — how we handle data safely and improve responsibly.

Fairness Without Compromise — bias safeguards and auditability measures.

Confidentiality Brief — controlled access and contractual safeguards.

Each resource is available under NDA to compliance, and security reviewers.

Enterprise-Grade

Safeguards for Insurers

pillars of SigmaSight

Security, privacy, fairness, and privilege are not afterthoughts — they are pillars of SigmaSight. Our independent audits, safeguards, and contractual protections give carriers confidence that their data, their strategy, and their clients are handled with the highest standards of trust.