Security: SOC 2 Type II, SOX-ready, ASOP-aware
Built for one of the most heavily regulated industries
Tesora was built by actuaries who understand the regulatory frameworks, and serves people who operate under those frameworks every day.
AICPA SOC 2 Type II badge
SOC 2 Type II audited, SOX-aligned, actuarial standards-aware
Tesora is audited annually against the AICPA SOC 2 trust services criteria for security, availability, processing integrity, and confidentiality.
Verify it yourself in the Trust Center
Live SOC 2 report, subprocessor list, and current control status on our Secureframe Trust Center. Procurement teams can request access in one click.
Your data stays yours
How customer data is stored, isolated, and used. For the formal collection and disclosure language, see our Privacy Policy.
On-prem or hosted in an isolated environment
Questions, documents, or a vulnerability to report?
Security questionnaires, document requests, and responsible disclosure all reach the team directly.
SOC 2 Type II
Audited annually against the trust services criteria for security, availability, processing integrity, and confidentiality.
SOX-aligned audit trail
Every change to a rate plan is recorded with reviewer, timestamp, model version, and source. Designed to survive a SOX walkthrough for carriers with public-company parents.
Aligned with the actuarial standards
Built to support actuaries operating under the Actuarial Standards of Practice, the AAA/CAS/SOA Code of Professional Conduct, the US Qualification Standards, and the CAS Statements of Principles.
No training on customer data
Customer rate plans, filings, books, and submissions are never used to train a shared model, under any contract and at any tier.
Per-tenant isolation
Each customer's data lives in a dedicated tenant. No cross-tenant inference, no shared embeddings, no shared vector store.
US-only data residency
Production data stays in US-region infrastructure (AWS us-east, us-west), and EU residency is available on request.
Encryption
AES-256 at rest, TLS 1.3 in transit, customer-scoped KMS keys, no plaintext PII in logs.
SSO, SAML, RBAC
Integrates with Okta, Azure AD, and Google Workspace, so roles stay granular and your own team controls who is provisioned.
Data source tracing
Every value Tesora populates traces back to the cell or page it came from. The provenance is preserved as a stable reference.
Hosted (most carriers)
A dedicated, isolated environment with full encryption and per-tenant isolation, managed and monitored by Tesora.
On-prem / your VPC
For carriers with internal-only model policies: model inference runs in the carrier's own VPC. Same audit trail, same control plane, same agents.