Security at CoverProof

We help you prove your security posture to insurers. That means our own security must be impeccable.

Encryption at Rest & In Transit

All data is encrypted using AES-256 at rest and TLS 1.3 in transit. Database connections use SSL certificates.

OAuth 2.0 Authentication

We use industry-standard OAuth 2.0 for all third-party integrations. We never store your passwords for connected services.

Minimal Data Access

We request only the permissions necessary to verify your security posture. Read-only access where possible.

SOC 2 Type II Infrastructure

Our infrastructure runs on SOC 2 Type II certified cloud providers with 99.9% uptime SLA.

Regular Security Audits

We conduct regular penetration testing and vulnerability assessments by third-party security firms.

Data Residency

Data is stored in US-based data centers. Enterprise customers can request specific data residency requirements.

Compliance & Certifications

SOC 2 Type II
In Progress2026
ISO 27001
Planned2026
GDPR Compliant
Compliant2025
CCPA Compliant
Compliant2025

What Data We Collect (and Don't)

Category✓ We Collect✗ We Never Collect
Identity DataUser counts, MFA status, admin rolesPasswords, personal emails, authentication tokens
Endpoint DataDevice counts, protection status, OS versionsFile contents, browsing history, user activity
Network DataFirewall rules, VPN configurations, network topologyTraffic logs, packet data, IP addresses of users
Backup DataBackup schedules, retention policies, success ratesBackup contents, file names, restore points

Integration Security

Microsoft 365 / Azure AD
OAuth 2.0 with delegated permissions. We request Directory.Read.All and Policy.Read.All scopes only.
Google Workspace
OAuth 2.0 with read-only admin directory access. No access to email or drive contents.
CrowdStrike / SentinelOne
API keys with read-only access. We verify device protection status only.
Firewall Configs
Configs are analyzed in-memory and not stored. Only rule summaries are retained.

Security Questions?

Our security team is available to answer questions and provide additional documentation.