Security and trust

Built for a regulated operation, from the first line.

Trisilva runs insurance operations for carriers, brokers, and channels across Southeast Asia. Keeping data in its home country, keeping every tenant separate, and holding a complete audit trail are platform concerns here, designed in rather than added after products ship. This page states plainly what we run today and the frameworks it is built to.

What we run today

Security controls built into the platform's architecture.

These are properties of how InsureFlow is built. Each is described plainly, because the advantage is in owning and operating it, not in hiding it.

Data residency and multi-region

01

Personal data stays on an in-country data plane in the region it belongs to. The Singapore control plane holds identity, tenancy, and configuration, and no personal data.

Residency is a property of the architecture, not a manual carve-out

Tenant isolation, end to end

02

Every carrier, broker, channel, and operations team runs under its own tenant identity and scope. One tenant's data is never visible to another, end to end.

Separation is verifiable across the whole platform, not per feature

Append-only audit trail

03

Every action, human or agent, lands on a system-wide, append-only audit log with full traceability, for compliance, dispute resolution, and billing verification.

A regulator review is answerable from the trail, by construction

Role-scoped access control

04

Access is least-privilege and role-scoped per tenant. A person or an agent sees only what its defined scope allows, and every scope is defined explicitly.

Scope is enforced by the platform and verifiable end to end

Encryption and document handling

05

Traffic to and within the platform is encrypted in transit. Binary attachments are handled by a dedicated Document Service, class-scoped to the product that owns them.

Documents cannot leak across a product or a tenant boundary

Secure by construction

06

Security is a gate in our AI Development Life Cycle. Every change clears an automated quality and conformance gate before it ships, against the open insurance standards stack.

Code meets the standard on arrival, rather than being corrected into it
Read the white paper: audit-clean multi-tenancy
Compliance posture

Built to the regimes of the markets we operate in.

We are a technology provider to regulated insurers. The platform is designed to the data-protection and financial-sector expectations their oversight requires.

Data protection regimes

Designed to Singapore's PDPA, Vietnam's Decree 13/2023 on personal data protection, and the data-protection expectations of Indonesia and the Philippines. Data-protection terms for each engagement are set out in the customer's Data Processing Agreement.

Financial-sector alignment

Aligned to the technology-risk and outsourcing direction set by financial regulators in the markets we serve, including the MAS in Singapore and the OJK in Indonesia. We build to the standards an insurer's oversight requires of its providers.

Audit-clean and verifiable

Tenant-clean audit trails are what make an outcome-based commercial model verifiable and a regulator review answerable. Reconciliation and discrepancy alerts run on the same trail.

Availability and incidents

Per-service availability and the full incident history are published on the status page rather than summarised here, and your team can subscribe there for incident notifications directly.

Documentation on request

What the Data Processing Agreement covers is set out in full. The agreement itself, the sub-processor list, and the security pack are released to a counterparty under the appropriate agreement, through Contact, rather than published.

Audit log · append-onlylive
09:41:07claim.triaged · CLM-4821 · tenant/vinfast-xdv#a7f3
09:41:08access.scope.checked · role/adjuster#a7f4
09:41:11document.attached · class/assessment#a7f5
09:41:14data.residency.enforced · region/vn#a7f6
09:41:19settlement.approved · scope/insurer-tenant#a7f7
09:41:19ledger.reconciled · outcome-fee/verified#a7f8
writing next entry…

Every action lands on the append-only trail, in real time.

Control frameworks

The frameworks the platform is built to.

Trisilva builds and operates its controls to the frameworks below. The security pack carries the control detail, the sub-processor list, and where certification stands for each.

Built to

ISO/IEC 27001

The international standard for an information security management system, and the framework most insurers ask for by name. Access management, change control, and incident response are built to it.

Built to

SOC 2 Type II

The trust services criteria for security, availability, and confidentiality, observed across a reporting period. Trisilva's controls are designed against the criteria.

Built to

ISO/IEC 42001

The management-system standard for artificial intelligence. It applies directly to an AI-first platform, so it is in scope from the start rather than added once the platform is large.

Adjacent frameworks the same programme covers: ISO/IEC 27701 for privacy information management, and Singapore's Data Protection Trustmark.

Running a security review?

Request the security pack, the Data Processing Agreement, and the sub-processor list. We will walk your team through the architecture and the controls.

Singapore · Vietnam · Indonesia · Philippines