Agency

Sweet

Data Security

Enterprise-grade protection for your agency and your clients.

At Sandcastle Technologies, we understand that New York State insurance agencies handle highly sensitive Personal Identifiable Information (PII) every single day. We built Agency Sweet with a security-first architecture so you can streamline your workflow without compromising on compliance or client trust.

1. Encryption Standards

We utilize industry-leading encryption protocols to ensure that your data is completely unreadable to unauthorized parties, whether it is sitting on our servers or traveling across the internet.

  • Data in Transit: All communications between your browser and our servers are encrypted using Transport Layer Security (TLS 1.2 or higher).
  • Data at Rest: All databases, document storage, and backups are encrypted at rest using AES-256 encryption, the standard adopted by the U.S. government.

2. Secure Cloud Infrastructure

Agency Sweet is powered by world-class cloud infrastructure providers. Our database and backend services are hosted in highly secure data centers that maintain strict physical and digital access controls. These underlying facilities hold rigorous compliance certifications, including SOC 2 Type II and ISO 27001.

3. Data Minimization & Retention

The safest data is the data you do not hold. Docu-Prepper is intentionally designed as a secure processing engine, not a permanent file cabinet.

Once you generate and download your policy packets, the temporary files are strictly scheduled for automatic deletion from our active servers. Your agency retains the final documents in your own compliant Agency Management System (AMS).

4. Authentication & Access Control

  • Secure Logins: We use modern, token-based authentication to ensure that only authorized users within your agency can access your specific workspace.
  • Strict Internal Access: Sandcastle Technologies enforces the principle of least privilege. Our engineers and support staff do not have access to your underlying Client Data unless explicitly granted temporary permission by you to resolve a specific technical support ticket.

5. Application Security

Our development lifecycle includes rigorous testing for common vulnerabilities (such as SQL injection and Cross-Site Scripting). We continuously monitor our application environment to detect, prevent, and respond to potential threats in real time.

Questions About Security?

If your compliance officer or agency principal has specific questions regarding our technical safeguards, infrastructure, or alignment with NYS DFS cybersecurity regulations, please reach out directly at:

info@agencysweet.com

Agency Sweet Logo

The ultimate personal lines workspace. Power your agency with Questionnaire for frictionless client intake and Docu-Prepper for flawless policy packets. Eliminate redundant data entry and keep your AMS perfectly organized.

© 2026 Agency Sweet. All rights reserved.