Security Overview

Security Built for Independent Insurance Agencies

AgencyStryde is designed with security, privacy, and reliability in mind. We use modern cloud infrastructure, secure authentication, role-based permissions, and encrypted communications to help protect agency and customer information.

TLS 1.3

Encryption in Transit

RBAC

Role-Based Access

Stripe

PCI-Compliant Payments

SOC 2

Infrastructure Partners

Last updated: June 26, 2026

Our Foundation

Security Principles

Every layer of AgencyStryde is built around six core security principles that guide how we design, build, and operate the platform.

๐Ÿ”’

Data Protection

Customer and agency data is encrypted in transit and protected by modern security controls. We take the safeguarding of sensitive insurance information seriously.

๐ŸŽฏ

Least Privilege Access

Users and systems receive only the permissions necessary to perform their functions. No component of AgencyStryde has broader access than it needs.

๐Ÿ—๏ธ

Secure Infrastructure

We build on trusted, enterprise-grade cloud providers with proven security track records, redundant architecture, and continuous monitoring.

๐Ÿ”„

Continuous Improvement

Security is not a one-time event. We continuously evaluate our controls, update our practices, and improve our posture as threats and technology evolve.

๐Ÿ›๏ธ

Customer Data Ownership

Your agency owns its data. AgencyStryde does not claim ownership of customer information. We act as a software provider, not a data owner.

๐Ÿ›ก๏ธ

Privacy First Design

Privacy protections are built into the platform from the start, not added as an afterthought. We collect only the data necessary to deliver the Services.

Cloud Infrastructure

Built on Trusted Providers

AgencyStryde is hosted and operated on best-in-class cloud infrastructure used by thousands of SaaS companies worldwide. We do not operate our own physical servers โ€” instead, we leverage providers with proven security programs, redundant architecture, and continuous uptime monitoring.

  • Managed cloud infrastructure with enterprise-grade reliability
  • Redundant hosting across multiple availability zones
  • Secure, automated deployment processes with rollback capabilities
  • Continuous infrastructure monitoring and alerting
  • Logical data separation between agency accounts
S

Supabase

Database, authentication & file storage

PostgreSQL-based managed database with row-level security, built-in auth, and encrypted storage.

V

Vercel

Application hosting & delivery

Global edge network with automatic SSL, DDoS protection, and zero-downtime deployments.

S

Stripe

Payment processing

PCI DSS Level 1 certified payment processor. AgencyStryde never stores full card numbers.

A

Anthropic

AI assistant (Ava)

Ava AI is powered by Anthropic. Data is processed under strict usage policies with no cross-agency sharing.

Controls

Data Protection

AgencyStryde employs multiple layers of technical controls to protect data in transit, at rest, and in use.

๐Ÿ”

Encryption in Transit

All communications between your browser and AgencyStryde are encrypted using TLS (Transport Layer Security). Data is never transmitted in plain text.

๐Ÿ”‘

Secure Authentication

User authentication is managed through Supabase Auth with industry-standard secure session tokens, bcrypt password hashing, and email verification.

๐Ÿ‘ฅ

Role-Based Access Controls

Access to features and data is restricted based on assigned roles. Users only see and interact with data appropriate to their permission level.

๐Ÿ“‹

Access Logging

Platform activity is logged to support security monitoring, incident investigation, and accountability across agency workspaces.

โฑ๏ธ

Session Management

User sessions are managed securely with appropriate timeout policies. Sessions are invalidated on logout and expire after periods of inactivity.

๐Ÿ›ก๏ธ

Password Protection

AgencyStryde enforces minimum password requirements. Passwords are hashed and never stored in plain text. Password reset flows use secure one-time links.

๐ŸŒ

Secure API Communications

All API requests between AgencyStryde services and third-party providers use authenticated, encrypted connections with scoped access tokens.

๐Ÿ—„๏ธ

Row-Level Security

Agency data is protected at the database level using row-level security policies that enforce agency-level data isolation.

๐Ÿšฆ

Input Validation

All user inputs are validated and sanitized on both the client and server side to protect against common injection and manipulation attacks.

Your Data. Your Agency.

We are a software provider โ€” not a data owner. Everything your agency enters into AgencyStryde belongs to you.

  • Agencies retain full ownership of all customer data
  • AgencyStryde never sells customer data to third parties
  • Customer data is never used for advertising or marketing
  • Customer information remains under agency control at all times
  • Data exports are available upon request

Your Data

Customer Data Ownership

Independent insurance agencies trust AgencyStryde with sensitive client information โ€” policy data, contact records, financial details, and more. We take that responsibility seriously.

AgencyStryde acts solely as a software service provider. We process your data to deliver the platform to you โ€” not to monetize, analyze, or share it with third parties for their own purposes.

Our Privacy Policy and Terms of Service include formal commitments regarding data ownership, retention, and access.

Access Management

User Access Controls

AgencyStryde gives agency owners full control over who can access their workspace, what they can do, and what data they can see. Access controls are managed at the agency level and enforced at the platform level.

  • Role-based permissions: Owner, Admin, and standard Team Member roles
  • Granular feature-level permission controls per user
  • Agency owners can add, remove, and modify team member access at any time
  • Agency-level data separation โ€” no cross-agency data access
  • All user actions are scoped to the authenticated agency workspace
  • Inactive or terminated team members can be immediately deactivated

Role Hierarchy

Owner

Full platform access. Manages billing, team members, and all agency settings.

Admin

Manages team, settings, and all operational features. Cannot manage billing.

Team Member

Access to assigned features and clients based on permissions granted by Owner or Admin.

Agency owners control access. You decide who joins your workspace and what they can see and do.

Payments

Payment Security

AgencyStryde uses Stripe โ€” the gold standard in payment security โ€” for all subscription billing and payment processing.

๐Ÿฆ

No Card Storage

AgencyStryde never stores full credit card numbers, CVVs, or sensitive card data on our servers.

๐Ÿ”

Tokenized Processing

Card data is tokenized by Stripe before transmission. Only secure tokens are stored and referenced.

โœ…

PCI Compliance

Stripe is a PCI DSS Level 1 certified payment processor, the highest standard for payment security.

๐ŸŒ

Secure Checkout

All payment collection occurs within Stripe's hosted, encrypted checkout environment โ€” not on AgencyStryde servers.

AI Assistant

Ava AI Security

Ava is AgencyStryde's built-in AI assistant designed to help agency teams work faster and smarter. Ava operates within the same security and permission controls that govern the rest of the platform.

  • Ava AI access is governed by the same role-based permission controls as all platform features
  • Agency data is never shared between separate agency accounts
  • Ava only generates responses from information the authenticated user is authorized to access
  • AI interactions are processed through Anthropic's API under strict data handling policies
  • Ava does not retain agency data between unrelated sessions for training purposes
  • Ava is a productivity assistant โ€” it does not make autonomous decisions or take actions without user input
๐Ÿค–

How Ava Handles Data

Data ScopeOnly your agency's authorized data
Cross-AgencyNo data shared between agencies
AI ProviderAnthropic (privacy-focused API)
PermissionFollows platform role controls
AutonomyUser-initiated only โ€” no auto-actions

Response

Incident Response

AgencyStryde maintains an internal Incident Response Plan that governs how we detect, investigate, contain, and communicate security events.

01

Detection & Monitoring

Continuous monitoring of platform activity, infrastructure health, and access patterns to identify unusual or potentially malicious behavior.

02

Investigation

Security events are investigated by AgencyStryde management with access to platform logs, access records, and infrastructure telemetry.

03

Containment

Affected accounts or systems are isolated or restricted. Suspicious access is revoked and affected credentials are rotated as needed.

04

Access Revocation

Compromised user accounts, API keys, or service credentials can be revoked immediately to prevent further unauthorized access.

05

Credential Rotation

Following a confirmed security event, relevant credentials, tokens, and secrets are rotated to restore a clean security state.

06

Customer Notification

Where required by law or where customer data may be affected, AgencyStryde will notify impacted customers in accordance with applicable notification requirements.

AgencyStryde maintains an internal Incident Response Plan.

Security questions or concerns? Contact us at support@agencystryde.com

Looking Ahead

Security Roadmap

Security is an ongoing commitment. Here are initiatives we are actively working toward to strengthen the platform's security posture.

Planned

Security Documentation Expansion

Expanding public-facing security documentation including technical controls, data flow diagrams, and third-party provider details.

In Progress

Audit Logging Improvements

Enhanced audit trail capturing for user actions, administrative changes, and sensitive data access events within agency workspaces.

Planned

Additional Access Controls

Expanding granular permission controls to support more fine-grained feature and data access management for growing agency teams.

Planned

Enterprise Security Features

Single Sign-On (SSO) integration, advanced session controls, and IP allowlisting for enterprise agency accounts.

Planned

Compliance Enhancements

Continued improvements to align with industry compliance frameworks relevant to insurance agencies and their data handling obligations.

Security Questions?

Reach out to the AgencyStryde team directly.

support@agencystryde.com

Security inquiries are reviewed by AgencyStryde management. We aim to respond within 2 business days.