Skip to content

Security and trust at Bindly

Security & trust

Your client data stays your client data.

Data is encrypted, access is controlled, and broker or insured information is never used to train foundation models.

Encrypted in transit & at rest

TLS 1.3 everywhere. AES-256 at rest. Per-tenant key isolation.

PII redaction by default

Sensitive identifiers are masked in logs and never used to train models.

Role-based access

Producer, CSR, and admin roles with granular permissions on every account.

US data residency

All conversation and submission data stays in US-region infrastructure.

Your data isn't training data

We never use broker or insured data to train foundation models. Period.

SOC 2 in progress

Type I underway with HIPAA-aligned controls already in place.

Subprocessors

These are the vendors that process data on Bindly's behalf, and why. We add to this list before a new vendor touches customer data.

VendorPurposeLocation
VercelApplication hosting and content deliveryUnited States
SupabaseDatabase, authentication, and file storageUnited States (us-west)
RailwayForms engine hosting (field extraction and form filling)United States
OpenAILarge language models for intake, extraction, form filling, summaries, and searchUnited States
StripeBilling and paymentsUnited States
ResendTransactional and lifecycle email deliveryUnited States
DocuSignElectronic signaturesUnited States
GoogleSign-in with Google; Gmail sending when a broker connects their mailbox; address autocompleteUnited States
MicrosoftOutlook sending when a broker connects their mailboxUnited States
PostHogProduct analytics (feature usage; session recording is off)United States
SentryError monitoringUnited States

AI and your data

Bindly uses large language models to collect, extract, organize, and validate submission information. We do not use broker data, insured submission data, or uploaded documents to train foundation models, ours or anyone else's. Sensitive identifiers are masked in logs, and conversation data stays in US-region infrastructure.

Nothing sends to a carrier or client on its own: a broker reviews and approves every outbound send and e-signature request.

Data retention and deletion

We retain information for as long as needed to provide the service, maintain business and security records, comply with legal obligations, resolve disputes, and enforce agreements. When information is no longer needed, we delete it or de-identify it, subject to backup and legal retention requirements.

Workspace owners can delete sessions and their filled-form data in-app at any time, and can request full workspace deletion by contacting us. See the privacy policy for the complete retention terms.

Backups and continuity

Customer data lives in a managed Postgres database with encrypted daily backups. Application hosting, the database, and the forms engine run on separate managed platforms so a failure in one does not take the record of your work with it.

Report a vulnerability

Found a security issue? Email security@bindly.insure and we'll respond within one business day. Please include steps to reproduce; we ask that you not access data that isn't yours while demonstrating an issue.

Working demo

Bring the packet that wastes your team’s time.

We will use your ACORDs and supplements to show exactly how Bindly turns repeated questions and follow-up into one clean insured interview.

  • See the insured and broker experience from start to finish.
  • Watch one answer carry across the full packet.
  • Leave knowing where Bindly fits and what it costs.

Your packet

not a canned sample

3,000+

ready forms

0

insured logins

Book your demo

Show us what you want fixed.

We will tailor the session to your packet, process, and team. No canned sales tour.

Next: choose a time on our calendar. Your information is used only to arrange the demo.