SECURITY & DATA PRACTICES

Trust requires more than a promise.

Litmus Risk is designed to protect sensitive insurance and household information while giving each firm control over its branded environment, users, and client relationships.

OUR APPROACH

Security built into the operating model.

Litmus Risk combines encrypted U.S.-based infrastructure, role-based access, managed identity, operational logging, backups, and contractual data-processing commitments. Customers remain responsible for their own systems, credentials, user assignments, and lawful instructions.

CORE CONTROLS

How information is protected.

These controls reflect the technical and organizational measures described in the Litmus Risk customer Data Processing Addendum.

01ENCRYPTION

Protected in transit and at rest

Public traffic is encrypted using TLS 1.2 or 1.3. Production data stores use AWS-managed encryption, including AES-256 server-side encryption for object storage and encrypted database and cache storage.

02ACCESS

Role-based by design

Role-based access controls limit platform visibility. Customer administrators configure branches, groups, advisors, agents, and client assignments so users work within their authorized scope.

03IDENTITY

Managed authentication

End-user authentication is managed through Auth0 by Okta with enforced password-complexity requirements. Access is revoked when authorized personnel no longer require it.

04INFRASTRUCTURE

U.S.-hosted AWS environment

Production infrastructure is hosted on Amazon Web Services in U.S. regions and uses AWS-native safeguards including web application firewall controls, security groups, and network access controls.

AI DATA PRACTICEClient personal data and Insurance Brokerage Data are not used to train AI models.

RESILIENCE & RESPONSE

Prepared to monitor, restore, and respond.

Operational safeguards are designed to preserve availability, document system activity, and support an organized response when an incident is suspected.

01

Backups

Aurora MySQL uses continuous point-in-time backups with 14-day automated retention. ElastiCache Redis uses seven-day snapshot retention.

02

Logging

Litmus Risk maintains production access and application logs, AWS WAF event logs, and database operational logs to support monitoring and investigation.

03

Incident response

A designated response process provides immediate escalation, investigation, mitigation, and contractual customer notification without undue delay and, where feasible, within 72 hours.

04

Data lifecycle

Processor data is returned or deleted after service termination according to the customer agreement and DPA, subject to backups and legally permitted retention requirements.

DATA GOVERNANCE

Clear roles. Limited use. Documented accountability.

Customer control

Customers control their branded tenant, authorized users, client relationships, permissions, and the information they direct Litmus Risk to process.

Processor commitments

When Litmus Risk acts as a processor or service provider, personal data is processed according to documented customer instructions, applicable agreements, and law.

Channel separation

Partner-agency client data is not provided to Litmus Insurance Solutions for sales, marketing, cross-selling, solicitation, quoting, or placement.

U.S.-only processing

The current DPA provides that personal data processing occurs within the United States unless a customer provides prior written consent for an approved transfer.

Privacy rights support

Litmus Risk supports customers in responding to applicable access, correction, portability, and deletion requests when Litmus Risk acts as their processor.

ENTERPRISE DILIGENCE

Review the details with us.

A customer DPA and additional security information are available during the evaluation and contracting process. Contractual terms control where they differ from this public summary.

Request security information