Skip to main content
Security & Trust

Built for E&O exposure.
Engineered for your audit.

We've sat in enough E&O renewal meetings to know what pulls a policy and what saves one. Koffyr is built around the audit trail your carrier will actually ask for.

Last updated July 2026 · This page and the PDF brief are maintained together.
E&O Export · sample · illustrative numbers
Cooper Insurance Group
✓ Tamper-evident
  • Period Jan 01 · 2025 — Dec 31 · 2025
  • Certificates issued 1,247
  • Self-service certs 843 (68%)
  • Avg time to issue 1.5 min
  • Guardrail blocks 11 (0.9%)
  • Disputes 0
SHA-256 · 9f3a…c41e · signed May 22, 14:08 UTC
01
TLS 1.2+ / AES-256
encryption · always-on
02
ESIGN Act / UETA
e-sign compliant · US
03
eIDAS AdES aligned
e-sign · EU forward-looking
04
US data residency
AWS · United States
On the roadmap
SOC 2 Type I
targeted Q4 2026
§ 01

Encryption everywhere

TLS 1.2+ in transit with TLS 1.3 negotiated. AES-256 at rest. All customer data, always. Key rotation is managed by Koffyr — never your problem.

§ 02

Hard tenant isolation

Row-level isolation in the database. S3 prefix isolation for documents. Cross-tenant access is prevented by multiple independent controls — row-level policy enforcement, service-layer scoping, and independently validated authorization sweeps.

§ 03

Immutable audit trail

Every action stamped + tamper-evident. One-click E&O export on every plan. Your carrier will thank you.

§ 04

E-sign compliance

ESIGN Act and UETA compliant — built in, not bolted on. No DocuSign middleware, no envelope fees, no “is this signature good enough?” guesswork. Aligned with eIDAS Advanced Electronic Signature (AdES) standards for future EU use.

§ 05

SOC 2 Type I — Q4 2026

SOC 2 Type I targeted for Q4 2026. Security policies are drafted and our control program is being built — current security questionnaire responses are available under NDA on request.

§ 06

US data residency

All customer data stored in US AWS regions. No transfers without explicit notice and your consent.

§ 07

Application-layer PII encryption

Sensitive fields (Tax ID / EIN, email, phone, date of birth, home address) encrypted at the application layer above database encryption — with keys held outside the application database. Consistent with DPA Schedule 2.

§ 08

Point-in-time backups

Continuous backups with point-in-time recovery, plus immutable weekly recovery points retained 35 days. Documented restore runbook in place; first full restore drill scheduled Q4 2026.

§ 09

Authentication

Passkeys (WebAuthn) are the primary authentication mechanism — phishing-resistant and strong by design. Email magic links provide a single-factor possession alternative. No passwords are stored. Session tokens carry a short TTL.

§ 10

Penetration testing & incident response

Third-party penetration test planned for Q4 2026, alongside SOC 2 Type I readiness. Incident response plan in place; full tabletop exercise scheduled before launch.

15 minutes · no slides

Book a demo. We'll show you the product.

Tell us a bit about your agency and your AMS — we'll come prepared, and walk you through what's shipping today.