Security
Getting a producer appointed means handling a Social Security number, banking details, and background screening results. That is why this page exists, and why it describes controls rather than displaying a badge we have not earned.
Controls at a glance
Six things that are true of every contracted producer and every agency, not of a premium tier.
Encryption in transit and at rest
Everything moves over TLS, including uploads, API traffic, webhook deliveries, and scheduled exports. Stored documents and records are encrypted at rest. There is no version of an account where either is switched off.
Least privilege access
Access is granted by role and by need rather than by seniority. A person who does not work your file does not see it, agency principals see their own structure and no other, and access is reviewed rather than accumulated.
Collection, not email
Sensitive items are collected through an authenticated upload rather than as attachments on a mail thread. Email is the wrong place for a Social Security number and it is also the hardest place to delete one from later.
Credential handling
API tokens are issued during onboarding, scoped to one structure, individually revocable, and separated per service so a rotation is a change rather than an outage. Webhook deliveries are signed.
Retention with an end date
Contracting records are retained to meet carrier and state obligations and then aged out, rather than kept indefinitely because deleting is harder than storing.
Incident response
A written runbook that is exercised rather than filed, and direct notification to affected producers naming what was involved and what we did, instead of a line on a status page.
What we hold, and how it is treated
Four categories. The first one is the reason the rest of this page is written carefully.
Identity and licensing data
Your legal name, address, date of birth, National Producer Number, license copies, and in most carrier packets a Social Security number, because carriers use it for producer identification and screening. This is the most sensitive category we hold and it is treated that way: collected through an authenticated upload, encrypted at rest, restricted to the people who prepare and submit your packets, and transmitted to a carrier only through the channel that carrier requires.
Banking details
Account details for commission payment, collected during onboarding and, at some carriers, collected by the carrier directly on the packet. We never ask for banking details by email or over an unrecorded phone call, and if you receive a request that looks like it came from us and asks you to change payment details, stop and call the published number instead.
Background screening results
Screening is part of carrier appointment. Results and any explanations you provide are held for the purpose of completing appointments, restricted to the people working your contracting, and retained for the period carrier and state requirements call for rather than kept as a permanent file.
Production and commission data
What you wrote, what was paid, chargebacks, and hierarchy. Visible to you, to an agency principal for their own structure, and to the people who reconcile statements. Hierarchy scoping is enforced at the data layer rather than by hiding a link in a screen.
How sensitive data reaches a carrier
A carrier packet exists to be sent somewhere else. The handling that matters is what happens between your upload and the carrier receiving it.
- Collected once, through an upload. Your producer profile is captured a single time through an authenticated upload in the contracting portal, not assembled from email attachments.
- Reused with your knowledge. The same profile populates each carrier packet you have agreed to. You are told which carriers a packet is going to before it goes.
- Sent the way the carrier requires. Each carrier specifies its own submission channel, typically its own portal or secure transfer. We use the channel the carrier requires rather than the one that is easiest for us.
- Minimized on the way out. A packet carries what that carrier asks for. We do not attach documents a carrier did not request on the theory that it might save a round trip.
- Carrier handling is the carrier\'s. Once a packet is submitted, the carrier holds that copy under its own controls and its own retention. We can tell you what we sent and when; we cannot speak for what happens to it afterward.
Access control and credentials
Two different doors, guarded differently. Both are scoped narrowly enough that losing one does not mean losing everything behind it.
People
- Role-based access, granted on need rather than on title, and removed when a role changes.
- Multi-factor authentication on the systems that hold producer data.
- Access to identity documents, banking details, and screening results restricted to contracting staff who are working that file.
- Periodic access reviews, so permissions granted for one project do not quietly become permanent.
- Separation between the staff who prepare packets and the staff who administer the systems.
Systems
- API tokens issued during onboarding, scoped to one agency structure, and revocable on their own.
- Hierarchy scoping enforced at the data layer, so a request for a producer outside your structure is refused rather than filtered in a screen.
- Separate tokens per service, so rotating one is a change rather than an outage.
- Signed webhook deliveries with a timestamp tolerance, so a captured payload cannot be replayed at you later.
- Exports written only to destinations you have named and confirmed.
The credential path and the event catalog are described in the integrations and data access reference.
Retention and subprocessors
Two questions a serious security review always asks, answered without hedging.
- Retention is set against obligations. Contracting records, appointment history, and commission records are kept for the period carrier agreements and state requirements call for, then aged out.
- Different records, different clocks. A screening result and a commission record do not need to live for the same length of time, and they do not.
- Subprocessors are reviewed. Any vendor that touches producer data is reviewed before use and periodically afterward, held to written confidentiality and security terms, and given the minimum access the job requires.
- Categories on request. We will describe the subprocessor categories and what each one touches in response to a security questionnaire.
- Leaving does not mean erasure. If you move to another organization, records we are required to retain stay retained. That is a regulatory obligation rather than a preference.
Compliance program
This section says exactly where the program stands, including the parts that are not finished.
What is true today
The controls on this page are running: encryption in transit and at rest, role-based least privilege access with multi-factor authentication, authenticated collection of sensitive documents, scoped and revocable credentials, hierarchy scoping enforced at the data layer, retention set against carrier and state obligations, and subprocessor review.
What is underway
Audit readiness work: control documentation, evidence collection, periodic access reviews, formal vendor and subprocessor review, policy management, and an incident response runbook that is exercised rather than filed. This is preparation for an audit, not the outcome of one.
What we will not claim
There is no completed SOC 2 report, no HIPAA attestation, no named auditor, no certificate number, and no badge on this page. When an audit is completed, this section will say so plainly and the report will be made available to contracted agencies and prospects under a non-disclosure agreement.
Incident response
Two commitments: you hear about an incident from us, and a researcher who finds something hears back from us.
- You hear it from us. If an incident affects your data, you get a direct notification naming what was involved and what we did, not a line on a status page.
- Operational issues are posted. Anything affecting contracting, submissions, statements, or platform access appears on the status page and goes to affected producers directly.
- A runbook that gets used. Detection, containment, assessment of what was affected, notification, and a written follow-up. Exercised rather than filed.
- Carrier and regulator obligations are met. Where an incident triggers a notification obligation to a carrier or a state, that notification happens, and you are told it happened.
- Beware payment change requests. We will never ask you to change banking details over email. If you get such a request, call the published number and confirm before acting.
Security contact
Security reports, questionnaires, and any question about how your data is handled go to contact@solvedsolutions.insure with a subject line starting "Security", or by phone on +1 (866) 415-6192.
Responsible disclosure
If you believe you have found a vulnerability in our systems or our sites, email the address above with enough detail to reproduce the issue. We acknowledge reports within one business day, keep you updated while we work, and will credit you when a fix ships if you want the credit. In return we ask that you give us a reasonable window to fix the issue before disclosing it publicly, that you do not access, modify, or retain data belonging to any producer or client, and that you do not degrade service for others while testing. Please do not run load tests, submit fraudulent contracting paperwork, or attempt social engineering against our staff or a carrier as part of a test. We will not pursue legal action against researchers acting in good faith within those terms.
Security questions arriving as part of an agency procurement process are welcome at the same address. Send the questionnaire and we will complete it, including the questions where the honest answer is not yet.
FAQs
Security questions
Are you SOC 2 certified?
No, and we will not imply otherwise. There is no completed SOC 2 report, no named auditor, and no certificate behind this page. Audit readiness work is underway: control documentation, evidence collection, periodic access reviews, subprocessor review, and an incident response runbook that gets exercised. That is preparation, not a result, and we would rather be believed about a smaller claim than doubted about a larger one.
Are you HIPAA compliant?
We have not completed a HIPAA audit or attestation and do not claim one. What we can describe is the control set on this page. If your arrangement involves protected health information, raise it during onboarding so we can talk through what we can and cannot support today rather than after something has already been sent.
Why does a carrier packet need my Social Security number?
Because carriers use it to identify a producer and to run the background screening that appointment requires. We collect it once through an authenticated upload rather than repeatedly by email, reuse it across the carrier packets you have approved, and transmit it only through the channel each carrier requires. If a carrier form asks for something we think is unnecessary, we will tell you, but we cannot change what a carrier asks for.
Who inside Solved Solutions can see my file?
The people who work it: your named contact, the contracting staff preparing and submitting your packets, and the staff who reconcile statements. Access is granted by role and by need and is reviewed rather than left to accumulate. An agency principal can see the producers in their own structure and no one else.
How long do you keep my data?
Long enough to meet carrier and state requirements for contracting and commission records, and then it ages out. Retention is set against those obligations rather than against convenience, and if you have a specific requirement in your own state, raise it and we will tell you what we can do.
Do you use subprocessors?
Yes, like any company that does not build its own infrastructure. They are reviewed before use and periodically afterward, held to written terms covering confidentiality and security, and given the minimum access the job requires. We will describe the categories and what each one touches in response to a security questionnaire.
How do I report a vulnerability?
Email contact@solvedsolutions.insure with a subject line starting "Security" and enough detail to reproduce the issue. We acknowledge reports within one business day and will not pursue legal action against researchers acting in good faith under the terms in the disclosure section on this page.
Something else? Contact us
Need the details in writing?
Send your questionnaire and we will complete it, including the parts where the honest answer is that the work is still underway.