At Sandcastle Technologies, we understand that New York State insurance agencies handle highly sensitive Personal Identifiable Information (PII) every single day. We built Agency Sweet with a security-first architecture so you can streamline your workflow without compromising on compliance or client trust.
1. Encryption Standards
We utilize industry-leading encryption protocols to ensure that your data is completely unreadable to unauthorized parties, whether it is sitting on our servers or traveling across the internet.
- Data in Transit: All communications between your browser and our servers are encrypted using Transport Layer Security (TLS 1.2 or higher).
- Data at Rest: All databases, document storage, and backups are encrypted at rest using AES-256 encryption, the standard adopted by the U.S. government.
2. Secure Cloud Infrastructure
Agency Sweet is powered by world-class cloud infrastructure providers. Our database and backend services are hosted in highly secure data centers that maintain strict physical and digital access controls. These underlying facilities hold rigorous compliance certifications, including SOC 2 Type II and ISO 27001.
3. Data Minimization & Retention
The safest data is the data you do not hold. Docu-Prepper is intentionally designed as a secure processing engine, not a permanent file cabinet.
4. Authentication & Access Control
- Secure Logins: We use modern, token-based authentication to ensure that only authorized users within your agency can access your specific workspace.
- Strict Internal Access: Sandcastle Technologies enforces the principle of least privilege. Our engineers and support staff do not have access to your underlying Client Data unless explicitly granted temporary permission by you to resolve a specific technical support ticket.
5. Application Security
Our development lifecycle includes rigorous testing for common vulnerabilities (such as SQL injection and Cross-Site Scripting). We continuously monitor our application environment to detect, prevent, and respond to potential threats in real time.
Questions About Security?
If your compliance officer or agency principal has specific questions regarding our technical safeguards, infrastructure, or alignment with NYS DFS cybersecurity regulations, please reach out directly at:
info@agencysweet.com
