Security & Trust

Built for regulated insurance environments.

Ubiquity runs in isolated tenants on hardened cloud infrastructure, with encryption everywhere, strict role-based access, and an immutable audit trail across every policy, quote and product change.

Controls

What's enforced by default

Encryption

TLS 1.2+ in transit. AES-256 at rest. Customer-managed keys (BYOK) available on enterprise plans.

Tenant isolation

Every business record is scoped by tenant_id at the database layer. Cross-tenant queries are structurally prevented.

RBAC

Role-based access with least-privilege defaults. Roles are stored separately from user profiles to prevent privilege escalation.

Audit trail

Every create, update and bind is logged with actor, timestamp and before/after state. Exportable for regulators.

Authentication

Email + password, social sign-in, and SSO (SAML) on enterprise plans. Session tokens are JWT with refresh rotation.

Snapshot on bind

Product configuration is snapshotted onto every policy at bind time — future product edits never alter in-force policies.

Data handling

Where your data lives and moves

Data residency

Hosted in the region of your choice (EU, US, MENA, APAC). Data does not leave the chosen region.

Retention

Retention windows are configurable per tenant and per data class to match local regulator requirements.

Export & deletion

Tenant data is fully exportable on request. On contract end, data is securely destroyed per agreed timelines.

Backups

Encrypted daily backups with point-in-time recovery. Restore tests run on a published cadence.

Subprocessors

Who we work with

A short, vetted list of subprocessors covers cloud hosting, authentication and email delivery. A current list is provided under NDA during procurement.

Talk to our security team

Procurement, infosec or architecture review — we'll walk through controls, residency and integration patterns with your team.