Skip to content

Security and trust

Built for people who will be audited on it

Our customers are regulated entities answering to boards, capacity providers, auditors and regulators. Security, data protection and AI governance are product requirements here, not a compliance page written after the fact.

Platform security

How your data is held

Written to be read by an information security team. We are happy to go deeper under a non disclosure agreement.

Deployment in your market

Each customer runs in a dedicated environment hosted in the market of the insurer. United Kingdom data remains in the United Kingdom, European Union data in the European Union, United States data in the United States. Personal data is not transferred outside the agreed region except on your documented written instruction and under an appropriate transfer mechanism.

Single tenancy

Your instance, your database and your encryption keys. Customer data, configuration and appetite rules are never pooled with those of another customer. Every record in the data model carries a tenant identifier so isolation is enforced at the data layer, not only by application logic.

Encryption

Data is encrypted in transit using current TLS, and at rest using industry standard algorithms with managed key services. Secrets are held in a managed secret store and never in source control.

Access control

Enterprise single sign on with your existing identity provider, multi factor authentication, and role based permissions mapped to your underwriting authority structure. Access follows least privilege and is reviewed on a defined cycle. Our engineers access production only through audited, time limited and individually attributable routes.

Auditability

The audit trail is append only. Every state change records the actor, the timestamp, what changed and what it changed from. Decisions can be reconstructed for internal audit, external audit, capacity providers and regulators long after the event.

Resilience

Automated backups with tested restoration, defined recovery objectives agreed with each customer, and monitoring with defined incident response and notification commitments set out in the services agreement.

AI governance

Assistive by design, and provably so

The governance question about AI in underwriting is not whether it is accurate. It is whether a decision can be explained afterwards. We designed for the second question.

No training on your data

Customer data is never used to train, fine tune or improve any model, ours or a third party's. Model providers are engaged under terms that prohibit training on submitted content.

Model agnostic

The AI layer is abstracted from any single provider. Models can be substituted, regionally restricted or removed to meet your sovereignty, procurement and model risk requirements.

No autonomous decisions

The platform does not automatically accept, decline, price or bind risk. AI output is a proposal placed in front of an accountable human, which keeps decision making inside your existing governance rather than outside it.

Evidence on every output

Extracted and generated values carry a confidence score and a citation to the source material, so an underwriter can verify rather than trust.

Minimisation

Prompts carry the data needed for the task. Personal data is minimised, and synthetic or pseudonymised data is used for evaluation and development wherever practicable.

Data protection

UK GDPR and EU GDPR

Where Syntxt processes personal data on behalf of a customer, the customer is the controller and Syntxt is the processor. We contract on that basis.

Our processor commitments

  • Process only on your documented instructions.
  • Appropriate technical and organisational measures against unauthorised or unlawful processing, loss, destruction or damage.
  • No sub processor without your prior authorisation, and equivalent obligations flowed down to any that are appointed.
  • Access limited to personnel with a business need, bound by confidentiality.
  • No transfer outside the agreed region other than in accordance with data protection law and your instructions.
  • Prompt written notification of any breach affecting your data, with full detail.
  • Assistance with data subject requests, impact assessments and regulator engagement.
  • Deletion or return of data at your election at the end of the engagement.
  • Information to demonstrate compliance, and a right of audit on reasonable notice.

Certification position

Syntxt is an early stage company and we will not claim certifications we do not hold. Our controls are designed against the ISO/IEC 27001 and SOC 2 control families, and formal certification is on our roadmap. We are happy to complete your security questionnaire, walk your information security team through our architecture and controls in detail, and agree contractual commitments that match the assurance you require in the interim.

For our full written policy, see the security policy.