Security: SOC 2 Type II, SOX-ready, ASOP-aware

Built for one of the most heavily regulated industries

Tesora was built by actuaries who understand the regulatory frameworks, and serves people who operate under those frameworks every day.

AICPA SOC 2 Type II badge

SOC 2 Type II audited, SOX-aligned, actuarial standards-aware

Tesora is audited annually against the AICPA SOC 2 trust services criteria for security, availability, processing integrity, and confidentiality.

Verify it yourself in the Trust Center

Live SOC 2 report, subprocessor list, and current control status on our Secureframe Trust Center. Procurement teams can request access in one click.

Your data stays yours

How customer data is stored, isolated, and used. For the formal collection and disclosure language, see our Privacy Policy.

On-prem or hosted in an isolated environment

Questions, documents, or a vulnerability to report?

Security questionnaires, document requests, and responsible disclosure all reach the team directly.

SOC 2 Type II

Audited annually against the trust services criteria for security, availability, processing integrity, and confidentiality.

SOX-aligned audit trail

Every change to a rate plan is recorded with reviewer, timestamp, model version, and source. Designed to survive a SOX walkthrough for carriers with public-company parents.

Aligned with the actuarial standards

Built to support actuaries operating under the Actuarial Standards of Practice, the AAA/CAS/SOA Code of Professional Conduct, the US Qualification Standards, and the CAS Statements of Principles.

No training on customer data

Customer rate plans, filings, books, and submissions are never used to train a shared model, under any contract and at any tier.

Per-tenant isolation

Each customer's data lives in a dedicated tenant. No cross-tenant inference, no shared embeddings, no shared vector store.

US-only data residency

Production data stays in US-region infrastructure (AWS us-east, us-west), and EU residency is available on request.

Encryption

AES-256 at rest, TLS 1.3 in transit, customer-scoped KMS keys, no plaintext PII in logs.

SSO, SAML, RBAC

Integrates with Okta, Azure AD, and Google Workspace, so roles stay granular and your own team controls who is provisioned.

Data source tracing

Every value Tesora populates traces back to the cell or page it came from. The provenance is preserved as a stable reference.

Hosted (most carriers)

A dedicated, isolated environment with full encryption and per-tenant isolation, managed and monitored by Tesora.

On-prem / your VPC

For carriers with internal-only model policies: model inference runs in the carrier's own VPC. Same audit trail, same control plane, same agents.