Security & data protection
ConvertRep handles lead, agent and policy performance data for regulated insurance businesses. Here's how that data is protected.
Encryption
All traffic is served over TLS 1.2+ with HSTS. Data at rest is encrypted with AES-256. Secrets and API credentials are held in a managed secret store and never committed to source control or exposed to the browser.
Tenant isolation and access control
Every record is scoped to a tenant and enforced at the database layer with row-level security, so one customer can never read another's data. Internal access is role-based, least-privilege, MFA-enforced and logged.
Monitoring and resilience
We monitor availability, error rates and anomalous access continuously. Backups are taken daily with point-in-time recovery, and restores are tested on a regular schedule.
Privacy by design
Marketing analytics on this website deliberately avoid personal data — for example we record an email domain, never the address. Read the full privacy policy.
Responsible disclosure
Found a vulnerability? Email security@convertrep.ai with steps to reproduce. We acknowledge reports within two business days and will not pursue action against good-faith research.
Questions from your risk team
We provide security questionnaires, data processing agreements and architecture reviews on request — start on the contact page, or see the platform overview on the home page.