Home / Security

Access and data handling

Security at Insurance Posture

Insurance Posture exists to verify security controls, so its own access model is deliberately minimal: read-only connections you consent to and can revoke in your own tenant, encrypted data isolated per organization, and no data sales.

Access model

Read-only by design

Connections to your environment are read-only. Scans collect configuration state from Microsoft 365, Entra ID, and Azure and make no changes. The platform cannot modify settings, create or delete users, alter policies, or write anything into your tenant, because it is never granted the permission to.

Access to Microsoft environments uses Microsoft Entra app registrations with certificate-based authentication and least-privilege read scopes. That means the scopes requested are the minimum needed to read the configuration controls carriers ask about on a cyber insurance questionnaire: things like MFA policy state, privileged role assignments, and email authentication settings.

You stay in control at every point:

  • You grant consent. The connection is authorized in your own Microsoft tenant by your own administrators. Nothing is connected without that consent.
  • You can revoke it at any time. Revocation happens in your tenant, on your schedule, without needing to contact SecValley. Once revoked, scans stop.
  • You can see exactly what was granted. The app registration and its read scopes are visible in your tenant like any other enterprise application.

This is the same standard we hold the environments we scan to. A product that checks whether your controls match what you told your carrier should itself be the easiest connection on your books to explain.

Data handling

How your data is handled

The data Insurance Posture holds falls into two categories: configuration state collected by read-only scans, and the documents you choose to upload, such as carrier applications and evidence files used to answer carrier requirements.

  • Encrypted in transit and at rest. Data moves over TLS and is encrypted at rest on the platform.
  • Isolated per organization. Uploaded applications and evidence files are stored per-organization and are not shared across customers. Your renewal application is yours alone.
  • Deleted on request. Customers control their data and can request deletion.
  • Never sold. SecValley does not sell customer data and receives no compensation from carriers or brokers. The product is paid for by the customers who use it, which is why the incentive is simply to show you an accurate picture. See pricing.

That independence matters in this category. A readiness picture is only worth trusting if the vendor producing it has no stake in the placement, which is also why SecValley is a security technology vendor and not an insurance carrier, broker, or agent.

Platform access

Access to the platform

The application itself is gated the way carriers expect your own systems to be gated.

  • Two-step sign-in. Signing in requires your email plus a one-time passcode, so a password alone is never enough.
  • Short-lived sessions. Sessions expire quickly rather than persisting indefinitely.
  • Role-based access. Team members only see the organizations they are granted. A consultant or MSP managing several organizations under one login sees each client's data scoped to that client, and an analyst granted one organization cannot browse another.

This scoping is what makes the multi-organization workflow described on the homepage safe: access follows explicit grants, not shared logins.

Hosting

Hosted on Microsoft Azure

The platform runs on Microsoft Azure. Hosting on the same cloud platform the product scans keeps the operational surface familiar and lets the platform build on Azure's underlying infrastructure security. Questions about hosting or data handling are welcome through the SecValley contact page.

Responsible disclosure

Responsible disclosure

Security researchers are invited to report suspected vulnerabilities in Insurance Posture or the SecValley platform through the SecValley contact page. We commit to acknowledging reports and working with reporters in good faith. Please give us a reasonable window to investigate and remediate before public disclosure, and do not access data that is not yours in the course of testing.

FAQ

Security questions, answered

Can Insurance Posture change anything in my environment?

No. Connections are read-only. Scans collect configuration state from Microsoft 365, Entra ID, and Azure and make no changes to the environment. The permissions granted are least-privilege read scopes, so the platform cannot modify settings, users, policies, or data in your tenant.

How do I revoke Insurance Posture's access?

In your own Microsoft tenant, at any time. Access is granted through a Microsoft Entra app registration that you consent to, and your administrators can revoke that consent or remove the app registration whenever they choose. Revocation does not require contacting SecValley, though you can also request deletion of collected data.

Where is my data stored?

The platform is hosted on Microsoft Azure. Data is encrypted in transit using TLS and encrypted at rest. Customers control their data and can request deletion. Subprocessors are listed in the published SecValley Data Processing Agreement; today they are Microsoft Corporation (Azure infrastructure and services) and Stripe, Inc. (payment processing).

Who can see my uploaded application?

Only members of your own organization who have been granted access. Uploaded applications and evidence files are stored per-organization and are not shared across customers. Within your organization, role-based access controls determine which team members see which organizations. SecValley does not sell customer data and receives no compensation from carriers or brokers.

Connect with confidence, revoke on your terms

Start with a read-only connection you control, run your first scan, and see your evidence-checked answers. When you are done, revoke access in your own tenant. Preparing for renewal? Start with the renewal readiness checklist.

Start your assessment