Published using the approved Security and Trust Centre claims registry and OAIC APP 11 context on 8 August 2026.
Why this matters
The OAIC's APP 11 guidance provides general context for reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. The exact controls appropriate to an organisation depend on its information and environment. As a policyholder, you do not need to audit a system yourself to ask clear questions. You can look for a current Security and Trust Centre, read the scope and exceptions beside each claim, and avoid treating a logo, adjective or generic assurance as proof of an outcome.
Key points to carry into the work
- Ask where the product says policy records are handled and whether the statement includes scope or exceptions.
- Ask how authenticated access and selected sharing are described without expecting a claim that all risk is removed.
- Look for a clear explanation of document storage and access paths instead of vague “secure by design” language.
- Check whether continuity, retention and incident reporting statements explain what they do not promise.
- 01Check data scope
- 02Ask about access
- 03Inspect document handling
- 04Read continuity limits
- 05Find reporting path
Ask five scoped security questions
Where Insia fits
Production services handling policy records and broker workflows use Australian-hosted AWS and Supabase infrastructure. Policy documents are encrypted, stored in private buckets and accessed through authenticated paths rather than public document links. Managed backups support continuity for production data services; backup scope, retention and restore procedures vary by service and data class.
Keep the boundary clear. Insia does not claim end-to-end or universal encryption, a risk-free access system, uninterrupted availability, no data loss, a certified security programme or a guaranteed incident response time.
Checklist
- Does each security answer state what service or data scope it covers?
- Are exceptions and limits shown beside the public claim?
- Can you distinguish private document storage from an open public link?
- Does the continuity statement avoid unsupported recovery promises?
- Can you find the current contact path for a privacy or security concern?
Sources and scope
Sources support the external context in this guide. Current product capability and availability are explained on the linked Insia product page.
Common questions
Does Australian data location mean no supporting provider ever processes data elsewhere?
No. Insia's public statement is scoped to production services handling policy records and broker workflows. It does not mean every supporting service or provider processes data only in Australia.
Does encryption mean every device and feature is protected in the same way?
No. Insia's document statement is scoped to configured private storage and authenticated access paths. It is not an end-to-end or universal claim across every provider, data class and device.
Do backups guarantee no data loss or immediate recovery?
No. Managed backups support continuity, while backup scope, retention and restore procedures vary by service and data class. No public recovery-time, recovery-point or no-data-loss promise is made.
Can I report a security concern?
Yes. Security concerns can be reported privately to hello@insia.com.au for assessment and the appropriate response path. The public statement does not promise a specific response time or outcome.
Is Insia certified to a security standard?
Insia does not claim a certification or formal assurance unless it can be evidenced. The Security and Trust Centre presents scoped controls, evidence requirements and exceptions instead.
Put the context to work
Keep this insurance record in one place.
Explore how the Insia App keeps policies, documents, renewal context and permissioned broker requests together in one iPhone experience.
Join the App waitlist