Claims data handled to Swiss standards
Policyholder claim data is among the most sensitive personal information a company can hold. Insurteam processes it under Swiss FADP and EU GDPR frameworks, with data residency in Switzerland.
FADP and GDPR compliance
Insurteam operates as a data processor under Swiss FADP and EU GDPR. Your insurer organisation remains the data controller; Insurteam acts only on your documented instructions.
Revised Federal Act on Data Protection
All policyholder data processed under the revised Swiss FADP. Data processing agreements available for review. Swiss data residency maintained throughout the processing pipeline.
General Data Protection Regulation
Insurteam's processing is compatible with EU GDPR data processor requirements. Standard contractual clauses available for EU-domiciled insurer clients. Data subject rights procedures documented and accessible.
Processor, not controller
Insurteam processes claim data only on the documented instructions of the insurer client. We do not use claim data for model training, profiling, or any purpose beyond the contracted processing agreement.
Defined retention periods
Claim data is retained for the duration specified in the processing agreement, typically 90 days post-settlement for audit purposes. Data destruction certificates available on request.
Encryption, access control, audit log
Encryption at rest and in transit
All claim data encrypted at rest using AES-256. Transport encrypted with TLS 1.3. API keys rotatable on demand.
Role-based access control
Principle of least privilege applied throughout. Separate API credentials per integration. Human operator access logged and reviewed quarterly.
Full audit trail
Every claim processing step logged with timestamp, operator ID, and data-access record. Audit log accessible via API and retained for the agreed period.
Swiss data residency
Processing infrastructure hosted in Switzerland. No data leaves Switzerland without explicit insurer instruction and contractual basis. Enterprise clients may request private cloud deployment.
Vulnerability management
Dependency scanning automated in the build pipeline. Security patches applied within 48 hours for critical advisories. Penetration testing conducted before major releases.
Incident response
Documented incident response plan with defined notification timelines. Data breach notification to affected insurer clients within 72 hours of confirmed incident.
Planned compliance milestones
FADP and GDPR DPA templates
Data processing agreements available for all insurer clients
AES-256 at rest, TLS 1.3 in transit
Encryption standard applied across all data stores and API endpoints
ISO 27001 certification
Information security management system audit initiated
Penetration test (third-party)
Annual third-party penetration testing programme
SOC 2 Type I readiness assessment
Controls audit aligned with SOC 2 trust service criteria
Talk to our team about your security requirements
Enterprise clients can request full data processing agreements, security questionnaire responses, and a dedicated review with our team before signing.