Built for a regulated operation, from the first line.
Trisilva runs insurance operations for carriers, brokers, and channels across Southeast Asia. Keeping data in its home country, keeping every tenant separate, and holding a complete audit trail are platform concerns here, designed in rather than added after products ship. This page states plainly what we run today and the frameworks it is built to.
Security controls built into the platform's architecture.
These are properties of how InsureFlow is built. Each is described plainly, because the advantage is in owning and operating it, not in hiding it.
Data residency and multi-region
01Personal data stays on an in-country data plane in the region it belongs to. The Singapore control plane holds identity, tenancy, and configuration, and no personal data.
Tenant isolation, end to end
02Every carrier, broker, channel, and operations team runs under its own tenant identity and scope. One tenant's data is never visible to another, end to end.
Append-only audit trail
03Every action, human or agent, lands on a system-wide, append-only audit log with full traceability, for compliance, dispute resolution, and billing verification.
Role-scoped access control
04Access is least-privilege and role-scoped per tenant. A person or an agent sees only what its defined scope allows, and every scope is defined explicitly.
Encryption and document handling
05Traffic to and within the platform is encrypted in transit. Binary attachments are handled by a dedicated Document Service, class-scoped to the product that owns them.
Secure by construction
06Security is a gate in our AI Development Life Cycle. Every change clears an automated quality and conformance gate before it ships, against the open insurance standards stack.
Built to the regimes of the markets we operate in.
We are a technology provider to regulated insurers. The platform is designed to the data-protection and financial-sector expectations their oversight requires.
Data protection regimes
Designed to Singapore's PDPA, Vietnam's Decree 13/2023 on personal data protection, and the data-protection expectations of Indonesia and the Philippines. Data-protection terms for each engagement are set out in the customer's Data Processing Agreement.
Financial-sector alignment
Aligned to the technology-risk and outsourcing direction set by financial regulators in the markets we serve, including the MAS in Singapore and the OJK in Indonesia. We build to the standards an insurer's oversight requires of its providers.
Audit-clean and verifiable
Tenant-clean audit trails are what make an outcome-based commercial model verifiable and a regulator review answerable. Reconciliation and discrepancy alerts run on the same trail.
Availability and incidents
Per-service availability and the full incident history are published on the status page rather than summarised here, and your team can subscribe there for incident notifications directly.
Documentation on request
What the Data Processing Agreement covers is set out in full. The agreement itself, the sub-processor list, and the security pack are released to a counterparty under the appropriate agreement, through Contact, rather than published.
Every action lands on the append-only trail, in real time.
The frameworks the platform is built to.
Trisilva builds and operates its controls to the frameworks below. The security pack carries the control detail, the sub-processor list, and where certification stands for each.
ISO/IEC 27001
The international standard for an information security management system, and the framework most insurers ask for by name. Access management, change control, and incident response are built to it.
SOC 2 Type II
The trust services criteria for security, availability, and confidentiality, observed across a reporting period. Trisilva's controls are designed against the criteria.
ISO/IEC 42001
The management-system standard for artificial intelligence. It applies directly to an AI-first platform, so it is in scope from the start rather than added once the platform is large.
Adjacent frameworks the same programme covers: ISO/IEC 27701 for privacy information management, and Singapore's Data Protection Trustmark.
Running a security review?
Request the security pack, the Data Processing Agreement, and the sub-processor list. We will walk your team through the architecture and the controls.
System status · What the DPA covers · Terms