Skip to content
Insia
Open menu
Resources
Trust and permissionsFor policyholders

Security Questions to Ask of an Insurance Record App

A non-technical security question list for insurance-record apps that prioritises scoped answers about access, documents, continuity and reporting.

Update note

Published using the approved Security and Trust Centre claims registry and OAIC APP 11 context on 8 August 2026.

Why this matters

The OAIC's APP 11 guidance provides general context for reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. The exact controls appropriate to an organisation depend on its information and environment. As a policyholder, you do not need to audit a system yourself to ask clear questions. You can look for a current Security and Trust Centre, read the scope and exceptions beside each claim, and avoid treating a logo, adjective or generic assurance as proof of an outcome.

Key points to carry into the work

  • Ask where the product says policy records are handled and whether the statement includes scope or exceptions.
  • Ask how authenticated access and selected sharing are described without expecting a claim that all risk is removed.
  • Look for a clear explanation of document storage and access paths instead of vague “secure by design” language.
  • Check whether continuity, retention and incident reporting statements explain what they do not promise.
From security label to scoped question
  1. 01Check data scope
  2. 02Ask about access
  3. 03Inspect document handling
  4. 04Read continuity limits
  5. 05Find reporting path

Ask five scoped security questions

1. What is the data-location statement?Look for the services and data types covered by the statement. A useful answer separates the relevant production scope from a claim that every supporting provider processes every kind of data in the same place.
2. How is access scoped?Ask how authenticated access, records and selected sharing relate to the approved user or broker relationship. Avoid treating a general access statement as proof that no unauthorised access can ever occur.
3. How are documents handled?Look for a clear distinction between private storage and public links, plus the scope of encryption language. This helps you understand the product boundary without exposing private implementation details.
4. What is said about continuity?A provider may explain backups and recovery handling by service and data class. Be cautious of an answer that promises uninterrupted access, no data loss or a recovery time without current evidence.
5. Where can a concern be reported?Find a published private contact route and the current privacy or security information. Reporting a concern starts an assessment process; it should not be described as a guaranteed incident outcome or timing commitment.

Where Insia fits

Production services handling policy records and broker workflows use Australian-hosted AWS and Supabase infrastructure. Policy documents are encrypted, stored in private buckets and accessed through authenticated paths rather than public document links. Managed backups support continuity for production data services; backup scope, retention and restore procedures vary by service and data class.

Keep the boundary clear. Insia does not claim end-to-end or universal encryption, a risk-free access system, uninterrupted availability, no data loss, a certified security programme or a guaranteed incident response time.

Checklist

  • Does each security answer state what service or data scope it covers?
  • Are exceptions and limits shown beside the public claim?
  • Can you distinguish private document storage from an open public link?
  • Does the continuity statement avoid unsupported recovery promises?
  • Can you find the current contact path for a privacy or security concern?

Sources and scope

Sources support the external context in this guide. Current product capability and availability are explained on the linked Insia product page.

Common questions

Does Australian data location mean no supporting provider ever processes data elsewhere?

No. Insia's public statement is scoped to production services handling policy records and broker workflows. It does not mean every supporting service or provider processes data only in Australia.

Does encryption mean every device and feature is protected in the same way?

No. Insia's document statement is scoped to configured private storage and authenticated access paths. It is not an end-to-end or universal claim across every provider, data class and device.

Do backups guarantee no data loss or immediate recovery?

No. Managed backups support continuity, while backup scope, retention and restore procedures vary by service and data class. No public recovery-time, recovery-point or no-data-loss promise is made.

Can I report a security concern?

Yes. Security concerns can be reported privately to hello@insia.com.au for assessment and the appropriate response path. The public statement does not promise a specific response time or outcome.

Is Insia certified to a security standard?

Insia does not claim a certification or formal assurance unless it can be evidenced. The Security and Trust Centre presents scoped controls, evidence requirements and exceptions instead.

Put the context to work

Keep this insurance record in one place.

Explore how the Insia App keeps policies, documents, renewal context and permissioned broker requests together in one iPhone experience.

Join the App waitlist
Join the App waitlist