Data Protection

Your data is safe.
By design, not by promise.

Encrypted under a key that’s yours. Never shared with carriers, competitors, or anyone else. Protected at the database itself, not just promised in a policy.

Three Ways It’s Protected

Can't be seen

Your records are encrypted under a key that's yours. No other operator, no carrier, and no Verinode employee can read them.

Can't be sold

Written into our Terms: your data is never provided to insurance carriers. Benchmarks are pooled and anonymized, so no single business can be picked out.

Can't be lost

Your data sits on its own isolated database, deployable in your region. Reached directly, it stays encrypted and unreadable. And you can export everything, anytime.

Your membership comes with your own key.

Your data is locked under a Vault Key that's yours, unlocked by your password. So your Chief Data Officer can keep working when you're offline, a separate, audited key handles the background, and every decryption is logged. The protection is in the architecture, not just the contract.

app.verinode.ai · My Vault

Your AI works for you. Only you.

Your Chief Data Officer reads your data only to hand you decisions, with every access logged. It never trains a shared model on your business, and never builds anything for a carrier. The only thing that leaves your account is anonymized aggregate, for the benchmarks you get back.

app.verinode.ai · Decisions

Never Shared With Anyone

Independence is the product.

Your data is never provided to carriers, TPAs, your competitors, or any other third party. We don’t share it, full stop. The commitment is written into the data-use policy and the Terms, and the Operator Advisory Council, active operators only, no carrier or TPA in the room, advises on that policy and holds us to it.

Common Questions

What operators ask about their data.

If I contribute my data, what stops it from being seen, sold, or stolen?

Three protections, one for each part. Seen: identifying columns are encrypted with a Vault Key scoped to you and never stored in plaintext, so no other operator or carrier can read them and no Verinode employee can browse or export them through any tool we run. Sold: the data-use policy, written into the Terms, commits that operator data is never provided to insurance carriers, and benchmark data is hashed and held to a minimum cohort size before publication. Stolen: row-level security is enforced at the database itself, and records stay unreadable in a breach without your authenticated session.

So can Verinode read my data?

Honest answer: our automated systems decrypt your data only to run the product you asked for, and only under that audited background key, with every access logged. That is what lets your Chief Data Officer work while you sleep. What cannot happen: another operator or a carrier reading your records, or a Verinode employee browsing or exporting them through any tool we operate. Operator-only key custody, where not even our own systems can read a slice, is on the roadmap. We won't claim it before it's true.

My current tools are SOC 2 certified. Isn't that enough?

SOC 2 is real, but it audits the controls a vendor has, not what they're allowed to do with your data. It does not stop a vendor that holds your keys from training models on your data or building benchmarks they sell to other customers. Verinode's commitments are the inverse: your data is tenant-isolated, decrypted only to run the product you asked for with every access logged, and never provided to carriers.

Is my data ever shared with carriers, competitors, or anyone else?

Not in identifiable form, ever. Your data is never provided to carriers, TPAs, or your competitors. Two things do touch it: anonymized aggregates power the peer benchmarks that are the reason to contribute, and a short, published list of subprocessors run the product itself (hosting, the LLM providers, and similar). Neither can trace a number back to your business. The commitment is written into the data-use policy and the Terms, and the Operator Advisory Council, restricted to active operators with no carrier or TPA in the room, reviews that policy and holds us to it. The independence is the product.

Can I export or delete my data?

Yes. You can request a full export at any time, and the data-use policy and privacy notice describe how deletion and data-subject requests are handled. Ownership of the underlying records stays with you.

Built to Be Trusted

The operators who share the most are the ones who trust the architecture.

Your data, protected at the database, working only for you, and never handed to the other side. Membership is how you put it to work.