New·Issue certificates without leaving your inbox: Coily for Outlook & Gmail is live.

Security & compliance

Built for the industry that reads the fine print.

The record you hand a regulator is the same record that issued the certificate. This page is the whole story: what isolates your data, what proves what happened, and what we will and will not claim.

HIPAA-ready

Anthropic BAA signed

Zero data retention

AI never retains or trains

PCI DSS SAQ-A

Card data never touches us

AES-256 + TLS

Encrypted at rest and in transit

Security is the issuance path.

Every certificate passes through FormLock™ before it exists: verified against the policy's actual endorsement forms, or routed to a licensed human. On every plan, with no configuration.

ReadMatchVerifyDecideProveInside FormLock →

Isolation the database enforces

One agency physically cannot query another's data. Enforced in Postgres, not just app code.

  • Row-Level Security on every table
  • Cross-tenant reads are impossible
  • Verified by two-org isolation tests

Identity & access

Every session is a verified identity with the least access its role allows.

  • MFA on every plan · SSO/SAML for Enterprise
  • Role-based permissions, DB-enforced
  • API secrets stored only as SHA-256 hashes

Auditability & proof

Who issued what, when, from which policy snapshot: an immutable record you can hand a regulator.

  • Append-only, trigger-immutable audit log
  • Tamper-evident SHA-256 (vrf_) proofs
  • Exportable Verification Reports

Compliance & privacy

Built to the frameworks that govern insurance data, represented honestly and evidenced rather than asserted.

  • GLBA-aligned safeguards for agency data
  • No PHI in today's product, and HIPAA-ready if that changes
  • No trackers, no data sales, no AI training on your data
Row-Level SecurityMFA · SSO / SAMLAppend-only audit logSHA-256 cert proofsGLBA-alignedUS data residency

Controls are continuously monitored and evidenced, not asserted.

Coily is in early access, and we don't claim certifications we haven't earned. Everything above describes controls you can verify. ACORD 25 certificates are commercial P&C data and carry no PHI; the AI layer already runs under a signed Anthropic BAA with zero data retention. A certificate is evidence of coverage, not a grant of it.

Questions your IT reviewer will ask? Send them here.