QuoteDeck is built on a foundation of Security by Design. We employ rigorous technical, physical, and administrative safeguards to ensure the confidentiality, integrity, and availability of your agency's data.
Data Infrastructure & Encryption
We utilize Amazon Web Services (AWS) to host our infrastructure, leveraging their world-class security protocols and HIPAA-eligible services.
- Encryption at Rest: All sensitive data—including client records, medical data, and quotes—is stored in AWS RDS using AES-256 encryption. This covers all primary databases, snapshots, and backups.
- Encryption in Transit: Every byte of data moving between your browser and our servers is protected using TLS 1.3 (Transport Layer Security) to prevent interception or tampering.
- Secure Key Management: Sensitive application fields use authenticated AES-256-GCM encryption. Production encryption secrets must be supplied through the deployment's protected secret manager and rotated under the operator's security policy.
Identity & Access Management (IAM)
- Mandatory Multi-Factor Authentication (MFA): In alignment with 2026 cybersecurity standards, MFA is strictly enforced for all administrative access. We provide and require MFA for all Agent accounts to block unauthorized access from credential theft.
- Role-Based Access Control (RBAC): We follow the "Principle of Least Privilege." Users are granted access only to the specific data sets and tools required for their professional roles within the agency.
- Modern Authentication: We use industry-standard identity providers that hash and salt passwords using high-entropy algorithms. QuoteDeck never stores passwords in plain text.
Auditing & Monitoring
- Submission Evidence: QuoteDeck records submission time, a privacy-preserving network identifier, a content hash, document seal data, and an append-only event trail for compliance-relevant form actions.
- Operational Monitoring: Deployments should connect application and infrastructure logs to their approved monitoring and incident-response system. Available controls do not substitute for an organizational monitoring program.
- Session Security: To protect data in shared environments, we enforce automatic session timeouts after 30 minutes of inactivity.
Resilience & Recovery
- Backups: Production database backup, retention, and point-in-time recovery settings are controlled by the deployment operator and should be tested against a documented recovery plan.
- Recovery Objectives: Recovery time and recovery point objectives must be documented and verified by the operating organization; the application does not claim a universal restoration SLA.
Compliance & Professional Standards
- HIPAA-Ready Technical Controls: The application provides encryption, MFA enforcement, scoped access, submission evidence, and audit capabilities that can support a compliance program.
- Contracts and BAAs: The operating organization is responsible for confirming that required agreements, including any applicable BAAs, are executed with every relevant vendor before regulated data is processed.
- No Certification Claim: Technical controls alone do not make a deployment HIPAA compliant or SOC 2 certified. Those outcomes require policies, training, risk assessment, vendor management, evidence collection, and—where applicable—independent examination.
For details on how we collect, use, and protect your personal information, please see our Privacy Policy.