Security & compliance
Built for the industry that reads the fine print.
The record you hand a regulator is the same record that issued the certificate. This page is the whole story: what isolates your data, what proves what happened, and what we will and will not claim.
Anthropic BAA signed
AI never retains or trains
Card data never touches us
Encrypted at rest and in transit
Security is the issuance path.
Every certificate passes through FormLock™ before it exists: verified against the policy's actual endorsement forms, or routed to a licensed human. On every plan, with no configuration.
Isolation the database enforces
One agency physically cannot query another's data. Enforced in Postgres, not just app code.
- Row-Level Security on every table
- Cross-tenant reads are impossible
- Verified by two-org isolation tests
Identity & access
Every session is a verified identity with the least access its role allows.
- MFA on every plan · SSO/SAML for Enterprise
- Role-based permissions, DB-enforced
- API secrets stored only as SHA-256 hashes
Auditability & proof
Who issued what, when, from which policy snapshot: an immutable record you can hand a regulator.
- Append-only, trigger-immutable audit log
- Tamper-evident SHA-256 (vrf_) proofs
- Exportable Verification Reports
Compliance & privacy
Built to the frameworks that govern insurance data, represented honestly and evidenced rather than asserted.
- GLBA-aligned safeguards for agency data
- No PHI in today's product, and HIPAA-ready if that changes
- No trackers, no data sales, no AI training on your data
Controls are continuously monitored and evidenced, not asserted.
Coily is in early access, and we don't claim certifications we haven't earned. Everything above describes controls you can verify. ACORD 25 certificates are commercial P&C data and carry no PHI; the AI layer already runs under a signed Anthropic BAA with zero data retention. A certificate is evidence of coverage, not a grant of it.
