Data Protection
Encrypted under a key that’s yours. Never shared with carriers, competitors, or anyone else. Protected at the database itself, not just promised in a policy.
Three Ways It’s Protected
Your records are encrypted under a key that's yours. No other operator, no carrier, and no Verinode employee can read them.
Written into our Terms: your data is never provided to insurance carriers. Benchmarks are pooled and anonymized, so no single business can be picked out.
Your data sits on its own isolated database, deployable in your region. Reached directly, it stays encrypted and unreadable. And you can export everything, anytime.
Your data is locked under a Vault Key that's yours, unlocked by your password. So your Chief Data Officer can keep working when you're offline, a separate, audited key handles the background, and every decryption is logged. The protection is in the architecture, not just the contract.

Your Chief Data Officer reads your data only to hand you decisions, with every access logged. It never trains a shared model on your business, and never builds anything for a carrier. The only thing that leaves your account is anonymized aggregate, for the benchmarks you get back.

Never Shared With Anyone
Your data is never provided to carriers, TPAs, your competitors, or any other third party. We don’t share it, full stop. The commitment is written into the data-use policy and the Terms, and the Operator Advisory Council, active operators only, no carrier or TPA in the room, advises on that policy and holds us to it.
Common Questions
Three protections, one for each part. Seen: identifying columns are encrypted with a Vault Key scoped to you and never stored in plaintext, so no other operator or carrier can read them and no Verinode employee can browse or export them through any tool we run. Sold: the data-use policy, written into the Terms, commits that operator data is never provided to insurance carriers, and benchmark data is hashed and held to a minimum cohort size before publication. Stolen: row-level security is enforced at the database itself, and records stay unreadable in a breach without your authenticated session.
Honest answer: our automated systems decrypt your data only to run the product you asked for, and only under that audited background key, with every access logged. That is what lets your Chief Data Officer work while you sleep. What cannot happen: another operator or a carrier reading your records, or a Verinode employee browsing or exporting them through any tool we operate. Operator-only key custody, where not even our own systems can read a slice, is on the roadmap. We won't claim it before it's true.
SOC 2 is real, but it audits the controls a vendor has, not what they're allowed to do with your data. It does not stop a vendor that holds your keys from training models on your data or building benchmarks they sell to other customers. Verinode's commitments are the inverse: your data is tenant-isolated, decrypted only to run the product you asked for with every access logged, and never provided to carriers.
Not in identifiable form, ever. Your data is never provided to carriers, TPAs, or your competitors. Two things do touch it: anonymized aggregates power the peer benchmarks that are the reason to contribute, and a short, published list of subprocessors run the product itself (hosting, the LLM providers, and similar). Neither can trace a number back to your business. The commitment is written into the data-use policy and the Terms, and the Operator Advisory Council, restricted to active operators with no carrier or TPA in the room, reviews that policy and holds us to it. The independence is the product.
Yes. You can request a full export at any time, and the data-use policy and privacy notice describe how deletion and data-subject requests are handled. Ownership of the underlying records stays with you.
Built to Be Trusted
Your data, protected at the database, working only for you, and never handed to the other side. Membership is how you put it to work.