Built for E&O exposure.
Engineered for your audit.
We've sat in enough E&O renewal meetings to know what pulls a policy and what saves one. Koffyr is built around the audit trail your carrier will actually ask for.
- Period Jan 01 · 2025 — Dec 31 · 2025
- Certificates issued 1,247
- Self-service certs 843 (68%)
- Avg time to issue 1.5 min
- Guardrail blocks 11 (0.9%)
- Disputes 0
Encryption everywhere
TLS 1.2+ in transit with TLS 1.3 negotiated. AES-256 at rest. All customer data, always. Key rotation is managed by Koffyr — never your problem.
Hard tenant isolation
Row-level isolation in the database. S3 prefix isolation for documents. Cross-tenant access is prevented by multiple independent controls — row-level policy enforcement, service-layer scoping, and independently validated authorization sweeps.
Immutable audit trail
Every action stamped + tamper-evident. One-click E&O export on every plan. Your carrier will thank you.
E-sign compliance
ESIGN Act and UETA compliant — built in, not bolted on. No DocuSign middleware, no envelope fees, no “is this signature good enough?” guesswork. Aligned with eIDAS Advanced Electronic Signature (AdES) standards for future EU use.
SOC 2 Type I — Q4 2026
SOC 2 Type I targeted for Q4 2026. Security policies are drafted and our control program is being built — current security questionnaire responses are available under NDA on request.
US data residency
All customer data stored in US AWS regions. No transfers without explicit notice and your consent.
Application-layer PII encryption
Sensitive fields (Tax ID / EIN, email, phone, date of birth, home address) encrypted at the application layer above database encryption — with keys held outside the application database. Consistent with DPA Schedule 2.
Point-in-time backups
Continuous backups with point-in-time recovery, plus immutable weekly recovery points retained 35 days. Documented restore runbook in place; first full restore drill scheduled Q4 2026.
Authentication
Passkeys (WebAuthn) are the primary authentication mechanism — phishing-resistant and strong by design. Email magic links provide a single-factor possession alternative. No passwords are stored. Session tokens carry a short TTL.
Penetration testing & incident response
Third-party penetration test planned for Q4 2026, alongside SOC 2 Type I readiness. Incident response plan in place; full tabletop exercise scheduled before launch.
The adjacent docs.
Sub-processors
Every vendor that touches data — SendGrid, Stripe, AWS, and Cloudflare. Authentication is in-house; no identity vendor sees your data.
Responsible disclosure
Find a vulnerability? Tell us first. Safe harbor, 90-day disclosure window.
Data Processing Agreement
Sign ours, or send yours. Standard contractual clauses for EU/UK customers.