SECURITY AND DATA

How We Protect Your Client Data.

Insurance client data is sensitive: names, DOBs, SSNs for underwriting, vehicle info, property details, policy numbers. Here is exactly how Agent Lead Engine stores, encrypts, and protects it.

PLATFORM SECURITY

SOC 2 Type II Compliant Infrastructure

The CRM platform powering ALE runs SOC 2 Type II attested, reviewed and audited annually.

Encryption In Transit

TLS 1.2+ on every connection, HTTPS everywhere, no plain text traffic across the platform.

Encryption At Rest

AES 256 encryption on stored data including contact records, messages, documents, and attachments.

Infrastructure

AWS backbone with segmented databases per subaccount. Isolated tenants.

Backups

Daily automated backups with point in time recovery. Geographically redundant.

Monitoring

24/7 infrastructure monitoring, anomaly detection, intrusion alerts.

Penetration Testing

Third party pen tests performed annually on the platform.

ACCESS CONTROL

Who Can See What

Role based access limits which staff touch which data.

01

User Roles

Admin, user, agent roles with granular permissions. Producers see only their contacts by default.

02

Two Factor Authentication

2FA available and recommended on every user account. Required for admin logins.

03

Audit Logs

Every login, every record view, every export logged and queryable.

04

Session Controls

Session timeout enforced, IP restrictions available on request.

DATA OWNERSHIP

Your Data Is Yours

No lock in, no hostage data.

Export On Demand

Full CSV export of contacts, conversations, opportunities, tasks any time from your dashboard.

Full Data Package On Offboarding

If you cancel, we deliver a complete data export package within 5 business days at no charge.

Deletion On Request

Permanent deletion of your account and all stored records upon written request.

No Reselling

We do not sell, rent, or share your client data with third parties. Ever.

No Training on Your Data

Your client records are not used to train third party AI models.

Vendor Subprocessors

List of processors (Twilio for SMS, SendGrid for email, etc.) disclosed on request.

RETENTION POLICY

How Long Data Is Kept

Data TypeRetentionReason
Contact RecordsLife of accountActive CRM use
Consent Records5 years minimumTCPA compliance
SMS Conversation History5 yearsConsent and audit trail
Call RecordingsConfigurable, default 90 daysTraining and dispute resolution
Email ArchivesLife of accountConversation continuity
Account After Cancellation30 days grace, then purgedAllows export or reactivation
INCIDENT RESPONSE

If Something Goes Wrong

No system is breach proof. Here is what happens if one is attempted against us.

Detection

Platform monitoring flags unusual activity. Security team investigates within hours.

Containment

Affected accounts isolated immediately, credentials rotated, access restricted.

Notification

Affected clients notified within state breach notification windows, typically 72 hours or less.

Have a Security Question?

We take this seriously. If you need docs for a carrier review or E&O audit, we will provide them.