Security & Data Practices
Cazimir is built for the regulatory environment insurance operates in. Three principles govern how the platform handles your data: every extracted value is traceable to its source document, a human reviews and approves outputs, and every extraction and correction is logged in an immutable audit trail.
This page explains where your data lives, how it is protected, and how our architecture keeps your organization’s data — and competitive intelligence — private to you.
Your Judgment Stays Yours. The Market’s Plumbing Gets Smarter for Everyone.
Each client’s documents, extracted data, schemas, business rules, and underwriting judgment are private to their organization, enforced by strict tenant isolation — one organization can never see or access another’s data. Your team’s corrections tune the platform to your operation, and that tenant-specific intelligence works for your organization exclusively.
Separately, Cazimir improves its general document-understanding capabilities — how accurately the platform reads an ACORD form, parses an SOV layout, or classifies a loss run — using de-identified, aggregated learning signals from across the platform. Before any signal leaves a client’s tenant, we strip all personal data, all client- and insured-identifying information, and anything reflecting a client’s underwriting criteria or risk appetite. What is shared is format knowledge, not business knowledge: every client benefits from the platform reading the market’s documents better, and no client’s confidential information or competitive judgment is ever exposed to, or deployed for, anyone else.
Clients with heightened requirements can elect a full opt-out from de-identified shared learning under their Master Service Agreement.
Where Your Data Lives
All data is hosted in the United States. The application runs on Railway; the database and file storage run on Supabase, backed by AWS infrastructure in us-east-1 (Virginia). EU hosting is available on both platforms and can be enabled for clients with UK or EU data residency requirements.
Encryption & Access
All data is encrypted in transit (TLS 1.3) and at rest (AES-256 via AWS). File uploads are encrypted at rest in Supabase Storage. Credentials and API keys are stored as environment secrets, never in code. Access to client data is restricted to the minimum necessary to operate and support the platform.
A Complete Audit Trail, Built In
Every extracted field links to its source document and page, with a confidence score. Every human correction is recorded in an immutable history. When a regulator, capacity partner, or E&O reviewer asks how a data point was produced, the answer is one click away — supporting compliance expectations under frameworks such as NAIC model guidance and the FCA Consumer Duty.
Certifications & Roadmap
Cazimir is an early-stage platform and does not yet hold independent certifications at the application layer. The underlying infrastructure providers (Supabase/AWS) are SOC 2 Type II certified. As the platform moves toward commercial launch, SOC 2 certification for the application layer is the natural next step on our roadmap.
We are happy to complete security questionnaires and to discuss the specific compliance requirements of your organization or capacity providers.
Frequently Asked Questions
Your documents, extracted data, and corrections are stored with strict tenant isolation, and anything identifying your business, your insureds, or your underwriting judgment improves the platform for your organization only. General document-format learning — how to read common insurance document types — is improved using de-identified, aggregated signals with all personal and client-identifying information removed first. A full opt-out is available under your Master Service Agreement.
In the United States: application hosting on Railway, database and file storage on Supabase (AWS us-east-1, Virginia). EU hosting can be enabled for clients with UK/EU data residency requirements.
In transit with TLS 1.3 and at rest with AES-256 via AWS. Uploaded files are encrypted at rest in Supabase Storage.
Access is restricted to the minimum necessary to operate and support the platform, with credentials managed as environment secrets — never stored in code.
You own your data at all times. If a pilot or subscription ends, your documents, extracted data, and audit logs are exportable on request and then deleted from our production systems. Your tenant-specific configuration is deleted and is never deployed for another client. Improvements to Cazimir’s general models made from de-identified, aggregated data during the term are retained — machine learning models cannot be selectively unwound — and these contain no personal data and nothing identifying your business.
Not yet at the application layer — Cazimir is early-stage. Our infrastructure providers (Supabase/AWS) are SOC 2 Type II certified, and application-layer SOC 2 is on our roadmap toward commercial launch. We’re glad to complete your security questionnaire in the meantime.
Every extracted field is evidence-linked to its source document and page, and every correction is logged immutably — providing the traceability expected under NAIC model guidance and the FCA Consumer Duty.
Questions From Your Compliance Team?
We’d rather answer them before the pilot than after. Send your security questionnaire or set up a call with the founding team.
