Your data, protected by design
Handle works with policy, client and payment data. The architecture was built with that in mind from day one, not added as a layer later.
- AES-256 at rest
- TLS 1.3 in transit
- Tenant isolation
- Audit logging
THE FOUR PILLARS
How it's built
- End-to-end encryption
- AES-256 at rest, TLS 1.3 in transit. No data travels or is stored in plain text.
- RAG on Demand
- The model accesses only the information the current task needs, at the moment it needs it. Your whole operation is never dumped into the context.
- API abuse protection
- Rate limits, anomaly detection and automatic blocking.
- Tenant isolation
- Each client's data lives separately. No shared model is trained on another brokerage's operation.
INFRASTRUCTURE
Where Handle runs
Handle runs on AWS with managed PostgreSQL databases. Language models are accessed via API from enterprise providers, under agreements that exclude the use of your data for training.
| Component | Detail |
|---|---|
| Cloud | Amazon Web Services (AWS) |
| Databases | Managed PostgreSQL |
| Language models | Enterprise providers, via API |
| Training on your data | Excluded by contract |
ACCESS CONTROLS
Who sees what, and how it's logged
| Control | Detail |
|---|---|
| Sign-in | SSO with your identity provider |
| Roles and permissions | Each user sees only what they should |
| Audit log | Every agent and user action is logged, with date and result |
| Revocation | Access removed immediately when someone leaves the team |
YOUR DATA, YOUR RULES
The credentials are yours. So is the data
Credentials for your insurer portals are stored encrypted and used only to run the tasks you authorize. You can revoke them at any time. If you stop using Handle, your data is deleted on request.
| Topic | Detail |
|---|---|
| Portal credentials | Stored encrypted |
| Use | Only for the tasks you authorize |
| Revocation | At any time |
| When you leave Handle | Your data is deleted on request |
FAQs
What your security team will ask
Are models trained on my data?
No. Each client's data is isolated, and our agreements with model providers exclude training.
How are portal credentials stored?
Encrypted, used only for authorized tasks, and revocable at any time.
Who can see agent activity?
Users with permission in your organization. Every action is recorded in the audit log.
What happens to my data if I stop using Handle?
It's deleted on request.
Does your security team need to review something in detail?
We'll share the documentation and answer their questions directly.


