Skip to content
Insia
Open menu

Security and Trust Centre

Protect the insurance records brokers and clients rely on.

See how access, Australian data location, encryption, backups, retention and incident response apply to Insia—and where a control has a specific limit.

Approved at the scoped wording recorded in this registry
Insia iOS profile settings showing data preferences, privacy, terms and support controls
Privacy and data controls in the Insia App.

How data is protected

Specific controls, written for the person assessing risk.

Each control names what it protects and any exception that matters. Insia does not imply a certification or universal assurance that has not been evidenced.

01

Australian data location

Production services handling policy records and broker workflows use Australian-hosted AWS and Supabase infrastructure.

This does not mean every supporting service or provider processes data only in Australia; service and data-class scope matters.

02

Access and tenant isolation

Insia uses authenticated access, explicit database grants, Row Level Security policies and private storage paths to scope insurance records to the approved user or broker relationship.

No access system is described as risk-free; production configuration is reviewed separately from the code contract.

03

Encryption and private documents

Policy documents are encrypted, stored in private buckets and accessed through authenticated paths rather than public document links.

This is not an end-to-end or universal-encryption claim across every provider, data class and device.

04

Backups and resilience

Managed backups support continuity for production data services; backup scope, retention and restore procedures vary by service and data class.

No public recovery-time, recovery-point, uninterrupted-availability or no-data-loss promise is made.

05

Retention and deletion

Records are retained as needed to provide the service and meet legal, security, dispute and operational obligations; deletion and backup, audit-log or broker retention can vary by context.

Identity checks, law, security, disputes, backups, audit records and broker obligations can affect timing and what can be deleted.

06

Incident and vulnerability reporting

Security concerns can be reported privately to hello@insia.com.au for assessment and the appropriate response path.

No guaranteed prevention, response time, notification deadline or independently certified response programme is claimed.

07

Providers and subprocessors

Insia uses service providers for hosting, public-site delivery, optional analytics and error monitoring, and enabled AI features; the data involved depends on the feature and configuration.

This public summary is not a contractual or exhaustive subprocessor schedule; request the current feature-specific data-flow scope for review.

Private reporting route

Raise a security or privacy concern through a private channel.

Keep credentials, customer information and unnecessary exploit detail out of the first message. The team can arrange an appropriate secure follow-up.

Email a private report
Book a broker workflow consultation