Built for regulated insurance environments.
Ubiquity runs in isolated tenants on hardened cloud infrastructure, with encryption everywhere, strict role-based access, and an immutable audit trail across every policy, quote and product change.
Controls
What's enforced by default
Encryption
TLS 1.2+ in transit. AES-256 at rest. Customer-managed keys (BYOK) available on enterprise plans.
Tenant isolation
Every business record is scoped by tenant_id at the database layer. Cross-tenant queries are structurally prevented.
RBAC
Role-based access with least-privilege defaults. Roles are stored separately from user profiles to prevent privilege escalation.
Audit trail
Every create, update and bind is logged with actor, timestamp and before/after state. Exportable for regulators.
Authentication
Email + password, social sign-in, and SSO (SAML) on enterprise plans. Session tokens are JWT with refresh rotation.
Snapshot on bind
Product configuration is snapshotted onto every policy at bind time — future product edits never alter in-force policies.
Data handling
Where your data lives and moves
Data residency
Hosted in the region of your choice (EU, US, MENA, APAC). Data does not leave the chosen region.
Retention
Retention windows are configurable per tenant and per data class to match local regulator requirements.
Export & deletion
Tenant data is fully exportable on request. On contract end, data is securely destroyed per agreed timelines.
Backups
Encrypted daily backups with point-in-time recovery. Restore tests run on a published cadence.
Subprocessors
Who we work with
A short, vetted list of subprocessors covers cloud hosting, authentication and email delivery. A current list is provided under NDA during procurement.
