Your data, protected by design

Handle works with policy, client and payment data. The architecture was built with that in mind from day one, not added as a layer later.

  • AES-256 at rest
  • TLS 1.3 in transit
  • Tenant isolation
  • Audit logging

THE FOUR PILLARS

How it's built

End-to-end encryption
AES-256 at rest, TLS 1.3 in transit. No data travels or is stored in plain text.
RAG on Demand
The model accesses only the information the current task needs, at the moment it needs it. Your whole operation is never dumped into the context.
API abuse protection
Rate limits, anomaly detection and automatic blocking.
Tenant isolation
Each client's data lives separately. No shared model is trained on another brokerage's operation.

INFRASTRUCTURE

Where Handle runs

Handle runs on AWS with managed PostgreSQL databases. Language models are accessed via API from enterprise providers, under agreements that exclude the use of your data for training.

ComponentDetail
CloudAmazon Web Services (AWS)
DatabasesManaged PostgreSQL
Language modelsEnterprise providers, via API
Training on your dataExcluded by contract

ACCESS CONTROLS

Who sees what, and how it's logged

ControlDetail
Sign-inSSO with your identity provider
Roles and permissionsEach user sees only what they should
Audit logEvery agent and user action is logged, with date and result
RevocationAccess removed immediately when someone leaves the team

YOUR DATA, YOUR RULES

The credentials are yours. So is the data

Credentials for your insurer portals are stored encrypted and used only to run the tasks you authorize. You can revoke them at any time. If you stop using Handle, your data is deleted on request.

TopicDetail
Portal credentialsStored encrypted
UseOnly for the tasks you authorize
RevocationAt any time
When you leave HandleYour data is deleted on request

FAQs

What your security team will ask

Are models trained on my data?

No. Each client's data is isolated, and our agreements with model providers exclude training.

How are portal credentials stored?

Encrypted, used only for authorized tasks, and revocable at any time.

Who can see agent activity?

Users with permission in your organization. Every action is recorded in the audit log.

What happens to my data if I stop using Handle?

It's deleted on request.

Does your security team need to review something in detail?

We'll share the documentation and answer their questions directly.