Data Security

Your Book Is Your Business.
We Treat It That Way.

Insurance agencies have been asking the right question: "What actually happens to my customer data?" Here's the complete, plain-English answer — no marketing fluff, no vague promises.

Encrypted in Transit & at Rest
Isolated Per Account
Never Sold or Shared
Deletable on Request
Minimum viable data

We Only Ask For What We Need.

To identify when a customer is back in market, Vera only needs one thing: a phone number to match against. Everything else is optional context that helps you prioritize outreach.

Field
Required?
Why We Need It
Phone Number
Required
Matched against market activity signals to detect shopping intent
Customer Name
Optional
Displayed in alerts so your team knows who to call
Renewal Date
Optional
Used to calculate days until renewal for risk scoring
State
Optional
Helps route alerts to the right agent or regional team
We Never Collect
Social Security numbers, policy financials, health records, bank account info, or any HIPAA-regulated PHI
Infrastructure

Built on AWS. Encrypted Everywhere.

Vera runs on Amazon Web Services infrastructure in the United States. Every layer of the stack applies encryption.

Encrypted at Rest

All customer data is stored in AWS Aurora PostgreSQL with AES-256 storage encryption enabled at the database layer. Data on disk is unreadable without the AWS-managed encryption keys.

Encrypted in Transit

All connections use TLS 1.2+ (HTTPS). There is no plain-text pathway to your data — not from the browser, not from API integrations, not from webhooks.

US-Only Infrastructure

Your data is stored and processed exclusively in AWS US-East data centers. No data is transferred, replicated, or processed outside the United States.

High Availability

Containerized deployments with rolling updates ensure zero downtime. The platform uses Kubernetes on AWS with automatic pod restarts and health monitoring.

Multi-tenant isolation

Your Customers Are Yours Alone.

Every record in the Vera database — every customer, every alert, every activity log — is tagged with your unique account identifier at the database row level. This is not a software-layer policy. It is enforced at the query level.

Your team can see your customers based on the role you assign them
CallVera support staff can access your data only for technical support, and only with full audit logging (you can see who accessed what)
Other Vera customers cannot see your data. Ever. The database enforces this regardless of any application-level code.
Third parties do not receive your customer data. We do not sell, license, or aggregate your book across our customer base.
Access controls

You Control Who Sees What.

Vera's permission model lets you define exactly what each team member can access — from viewing alerts to managing integrations to exporting data.

Role-Based Access

Assign admin, agent, or read-only roles. Each role has a defined, non-overlapping permission set.

JWT Authentication

All sessions use signed JSON Web Tokens. Sessions expire automatically and cannot be forged.

Audit Log

Every admin action — customer uploads, setting changes, user management — is logged with a timestamp and the identity of who performed it.

API Key Controls

If you integrate Vera with a CRM or dialer via API, each integration uses a scoped API key that you can revoke at any time.

New: Secure Upload

Your Phone Numbers Can Stay
In Your Browser Forever.

For clients who want zero risk, we built a client-side hashing option. When Secure Mode is enabled, your phone numbers are cryptographically hashed in your browser before anything is sent. We receive one-way fingerprints — mathematically impossible to reverse back into real numbers.

01

You upload your CSV

Your customer file is loaded into your browser. Nothing has left your machine yet.

02

Your browser hashes every phone number

Using HMAC-SHA256 with a key unique to your account, each phone number is converted to a 64-character fingerprint — entirely inside your browser tab. The raw number is discarded immediately.

03

Only the fingerprints are sent

We receive something like a3f2c9b1d8e74f... — never +15551234567. Your real phone numbers are never transmitted, never stored, never seen.

04

Matching still works perfectly

When a caller pings in, we hash their number the same way and compare fingerprints. A match fires your alert instantly — with zero knowledge of the actual phone number on either side.

What makes this different from other solutions: Most vendors ask you to “trust us” with your data. Secure Mode eliminates the need for trust entirely. We provably cannot reconstruct your customer list from what we store — not because of policy, but because of math.
How matching works

Your Book Stays In Your Account.
The Match Comes To You.

The most common concern is: "Does my customer list get mixed with other agencies' data to do the matching?" No. Here's exactly what happens.

01

You upload your book

Customer records are stored in your isolated account on our encrypted database. They do not leave your account.

02

Market signals arrive

Vera receives real-time market activity signals (inbound insurance shopping calls and intent indicators) from our publisher network. These signals contain phone numbers, states, and timing — nothing personally identifying beyond a phone number.

03

Server-side matching

Our platform checks each incoming signal against your customer book on our servers. This comparison happens entirely within our infrastructure — your book never travels to a third-party matching service.

04

Only your matches are shown to you

When a phone number matches a customer in your book, an alert is created in your account only. Other agencies using Vera see their matches. You see yours. Never each other's.

Two upload options

Choose Your Comfort Level.

Both modes give you full matching capability. The difference is how much trust you need to place in us.

Standard Upload
  • Phone numbers stored encrypted on AWS Aurora
  • Tenant-isolated — no cross-account access
  • Deletable at any time
  • Requires trusting our infrastructure
Most clients use this. It's fast and straightforward.
Secure Mode Upload
  • Phone numbers hashed in your browser — never transmitted
  • We store one-way fingerprints only
  • Mathematically impossible for us to reconstruct your book
  • Requires zero trust in our infrastructure
Built for clients where data residency or privacy compliance is a hard requirement.
Your rights

You Own It. You Can Delete It.

Export anytime

Download your full customer book at any time from your account settings. No questions, no friction, no delay.

Delete on demand

Delete individual customers or your entire book from within the platform. Deletion is immediate and permanent.

Leave with your data

If you cancel, your data is available for export during the offboarding window and then permanently deleted from our systems.

Data processing agreement

We provide a Data Processing Agreement (DPA) for enterprise clients. Request one from your account manager before or during onboarding.

Honest answers

Questions We Know You'll Ask.

Can CallVera employees see my customer data? +

Yes — as the platform operator, our engineering and support team can access data for debugging, support, and technical operations. This access is always logged and auditable. We will never access your data for competitive intelligence or share it externally. If your concern is platform-provider access, we recommend reviewing and signing our Data Processing Agreement, which formalizes these obligations contractually.

Is Vera HIPAA compliant? +

Vera is not a HIPAA-covered system by design. We intentionally limit the data we collect to avoid PHI: we do not accept or store medical diagnosis, treatment records, insurance claim details, or any other Protected Health Information. The data we process (name, phone, state, renewal date) does not constitute PHI under HIPAA. If your use case requires a HIPAA Business Associate Agreement, contact us to discuss your specific requirements.

Are you SOC 2 certified? +

We are not yet SOC 2 certified. We are building toward it. For now, we can provide detailed documentation of our security controls, infrastructure configuration, and data handling practices upon request. Most insurance agencies find that our architecture documentation, DPA, and transparent answers here are sufficient. If SOC 2 is a hard requirement, let us know — we want to earn your business on a timeline that works for both sides.

What if there's a data breach? +

In the event of a confirmed data breach affecting your account, we will notify you within 72 hours of discovery, provide a detailed incident report, and work with you on remediation. Our data minimization approach means a breach of our systems would expose the minimum viable data (primarily phone numbers and names) — not financial, medical, or identity documents.

Can I get a copy of your security documentation? +

Yes. We can provide infrastructure diagrams, data flow documentation, our Data Processing Agreement, and a detailed written security controls summary. These are available under NDA for qualified prospects during the sales process. Reach out via the form below or to your account manager.

Do you train AI models on my data? +

No. Your customer data is never used to train AI models — ours or anyone else's. The AI features in Vera (like Vera's chat assistant) use your operational data to answer questions you ask, but that data is not retained by Anthropic (our AI provider) for training per our enterprise agreement terms.

Still have questions?

Talk to a Human About Security.

We'll answer every question — including the ones that make most vendors uncomfortable. No evasion. No script.

We can provide a Data Processing Agreement, infrastructure documentation, and detailed security Q&A for your compliance team.