Last updated: 10 June 2026
At Sencov, protecting the data entrusted to us by our customers, partners, and policyholders is foundational to our business. As an insurance technology platform, we handle sensitive personal and policy data, and we operate a formal Information Security Management System (ISMS) to keep it confidential, available, and accurate.
This page summarizes the technical and organizational controls we maintain. Formal documentation, including our ISO/IEC 27001 certificate, and independent penetration test summaries are available to qualifying partners on request.
1. Governance and our security program
Our security program is built on a formal ISMS aligned with ISO/IEC 27001:2025 and informed by ISO/IEC 27002, the NIST Cybersecurity Framework, and industry best practice. The ISMS is governed by documented policies, owned by senior management, reviewed at least annually, and supported by a risk-management process that identifies, assesses, and treats information security risks on a continual basis.
Security responsibilities are formally assigned, and an internal security function oversees policy enforcement, monitoring, vulnerability management, and incident response.
2. Compliance and certifications
| Standard / attestation | Status |
|---|---|
| ISO/IEC 27001:2025 (Information Security Management System) | Certified |
| Independent penetration testing (VAPT) | Performed periodically |
Our control framework aligns with ISO/IEC 27002 control objectives and the NIST Cybersecurity Framework functions (Identify, Protect, Detect, Respond, Recover).
3. Data encryption
We encrypt customer and personal data both in transit and at rest using strong, industry-standard algorithms.
Encryption in transit. All data transmitted between users, APIs, and our services is encrypted using TLS 1.2 or higher (TLS 1.3 preferred). We enforce HTTPS across all public endpoints, use HTTP Strict Transport Security (HSTS), disable known-weak ciphers and protocols, and use certificates from reputable certificate authorities.
Encryption at rest. All data stored in our production databases, object storage, backups, and disk volumes is encrypted at rest using AES-256 (Advanced Encryption Standard, 256-bit). This includes primary data stores, replicas, and backup media.
4. Encryption key management
Encryption keys are managed within a dedicated Key Management Service (KMS) backed by our cloud provider's hardware security modules (HSMs).
- Keys are generated, stored, and used inside the KMS; they are never stored alongside the data they protect, and plaintext key material is not exposed to applications or personnel.
- Access to keys is restricted to authorized services and roles under the principle of least privilege, with all key usage logged and monitored.
- Automatic key rotation is enabled, and separation of duties is enforced between those who manage keys and those who manage data.
- Encryption keys are not shared with third parties.
- Production data is logically segregated per tenant, so one customer's data is isolated from another's.
For enterprise engagements involving Highly Confidential data, dedicated key isolation and customer-managed key (BYOK) arrangements can be evaluated on request.
5. Data classification and handling
We classify data so that controls are applied proportionate to sensitivity. Each tier carries defined handling, access, encryption, and retention requirements.
| Classification | Examples | Handling |
|---|---|---|
| Public | Marketing content, public documentation | No restrictions |
| Internal | Internal docs, non-sensitive operational data | Access limited to personnel |
| Confidential | Customer account data, business data | Encrypted at rest and in transit; role-based access |
| Highly Confidential / Restricted | Personal data, policy and claims data, credentials, financial identifiers | Encrypted with AES-256; strict least-privilege access; access logged and monitored; isolated handling |
Personal and policyholder data is treated as Highly Confidential / Restricted and receives our strongest controls.
6. Security architecture
We apply defense-in-depth across our platform:
- Services run in a segmented cloud network (private subnets / VPC) with security groups and network access controls restricting traffic to what is required.
- Public-facing applications sit behind a Web Application Firewall (WAF) and DDoS protection.
- Production, staging, and development environments are logically separated; production access is tightly restricted.
- Administrative access to infrastructure requires authenticated, least-privilege access over encrypted channels.
- Infrastructure is provisioned through reviewed, version-controlled configuration to ensure consistent, hardened baselines.
A more detailed security architecture overview is available to qualifying partners under NDA.
7. Access control and authentication
Role-based access control (RBAC) and the principle of least privilege govern all access to systems and data.
- Multi-factor authentication (MFA) is enforced for administrative and remote access to production systems.
- Access is provisioned through a formal joiner/mover/leaver process, reviewed periodically, and revoked promptly on role change or departure.
- Privileged access is restricted, logged, and monitored.
8. Secure development lifecycle (SDLC)
Security is integrated into our software development lifecycle, including peer code review and segregation of duties for deployments.
- We use automated static (SAST) and dynamic (DAST) application security testing and dependency / software composition scanning to detect vulnerabilities before release.
- Changes follow a documented change-management process with testing and approvals.
- Secrets and credentials are managed through a secrets manager — never hard-coded in source.
9. Infrastructure and cloud security
Our platform is hosted on AWS in Mumbai, India leveraging the provider's certified physical and environmental security controls. We maintain hardened configurations, timely patching of systems, and continuous configuration monitoring. Physical data-center security (access controls, surveillance, environmental safeguards) is inherited from our cloud provider's audited facilities.
10. Logging, monitoring, and threat detection
Security-relevant events and access logs are centrally collected and retained. Automated monitoring and alerting detect anomalous or suspicious activity. Logs are protected against tampering and reviewed as part of our detection and response process.
11. Vulnerability and patch management
We perform regular automated vulnerability scanning of infrastructure and applications. Identified vulnerabilities are triaged by severity and remediated within defined timeframes. Independent third-party penetration testing is conducted at least annually and following significant changes; findings are tracked to closure.
12. Incident response
We maintain a documented incident response plan with defined roles, severity classification, escalation paths, and post-incident review. In the event of a security incident affecting customer or personal data, we follow defined containment, investigation, and remediation steps and will notify affected customers and applicable authorities without undue delay in line with our contractual and legal obligations.
13. Business continuity and disaster recovery
Data is backed up regularly; backups are encrypted and their restoration is tested periodically. We maintain business continuity and disaster recovery plans with defined recovery objectives (RTO/RPO) to restore service in the event of disruption.
14. Data retention and deletion
Personal and customer data is retained only as long as necessary for the purposes for which it was collected and to meet legal, regulatory, and contractual obligations. On expiry or valid request, data is securely deleted or anonymized. See our Privacy Policy for details.
15. Personnel security
Employees and contractors are subject to background screening where permitted by law. All personnel sign confidentiality agreements and complete security and privacy awareness training at onboarding and periodically thereafter. Access to data is granted strictly on a need-to-know basis.
16. Third-party and vendor risk management
We perform security due diligence on sub-processors and vendors that handle data on our behalf, and bind them to contractual data-protection and confidentiality obligations. We do not use third-party systems to store, access, or process customer information without ensuring appropriate safeguards are in place. A current list of sub-processors is available at Sub-processors.
17. Privacy and data protection
We process personal data in line with applicable data protection laws and our Privacy Policy, which describes what we collect, how we use it, retention, international transfers, and the rights available to data subjects.
18. Responsible disclosure
We welcome reports from the security community. If you believe you have found a security vulnerability, please contact us at infosec@insure.one. We will acknowledge your report, investigate, and remediate as appropriate. Please act in good faith, avoid accessing or modifying data that is not yours, and give us reasonable time to respond before public disclosure.
19. Requesting documentation
Qualifying partners and customers may request the following under a non-disclosure agreement by contacting infosec@insure.one:
- ISO/IEC 27001:2025 certificate
- Penetration test executive summary
- Security architecture overview
- Information Security Policy summary
For security inquiries, contact infosec@insure.one.