Effective: 2026-06-09 · Pilot-phase posture. Reflects
the actual controls in place, not aspirational language.
Plain-English summary. Your commission statements and AMS
export sit in an encrypted folder on a US server in Chicago. Only you
and the founder can see them. We never share with carriers or other
agencies. We delete everything 30 days after you cancel — sooner if
you ask. We have not had a breach. We use GLBA Safeguards Rule
practices because every state-licensed agency is covered. We are not
SOC 2 certified yet (targeting Type I within 6 months of pilot #10);
if your E&O carrier requires SOC 2 today, this isn't for you yet.
The detail below is what an IT or E&O reviewer will want to read.
From cycle uploads: carrier commission statement CSV + AMS export CSV per cycle
Operational: SHA-256 hash of your access key (never the raw key), Fly-Client-IP hash (per-day-rotating, never raw IP), user-agent string (first 200 chars), audit log of every action
What we DON'T collect: social security numbers, payment card details (Stripe handles those), browser fingerprints, third-party analytics cookies
Where data lives
Processing runs on a Fly.io machine in ord (US-Central, Chicago)
Storage is a per-tenant directory on a 1 GB Fly volume mounted at /data
Data at rest sits on Fly.io's managed volume infrastructure; we rely on Fly's platform-level storage protections rather than an at-rest cipher layer we operate ourselves (ask for Fly's current security posture if your reviewer needs specifics)
TLS termination at Fly's HTTPS edge; HSTS enforced
Anthropic — Claude API for carrier-statement PDF extraction and carrier-reply analysis (paid tier only). Receives carrier statement PDF content and pasted carrier-reply text. Anthropic does NOT train on API inputs per their commercial terms.
Resend — transactional email. PII-bearing email content stored for 7 days (paid tier) or 30 days (free tier) for delivery monitoring.
Stripe — billing (Phase B+). Handles all payment card data per PCI scope
Retention
Active pilot data: retained for the duration of the pilot
After pilot termination: 30-day grace period, then purged
Soft-deleted cycles: 30-day grace before hard purge
Audit chain: retained for 7 years (industry-standard for financial records). The chain is tamper-evident via SHA-256 prev_hash linkage — any post-write modification of an entry invalidates the chain from that point forward and is surfaced by cowork audit verify-chain.
Earlier purge: request at any time via info@coworkrecon.com; executed within 5 business days
Your rights
Access: request a copy of all data we hold about your agency
Correction: edit your agency name + contact email self-serve on the Settings page
Deletion: email us. Self-serve deletion UI is on the roadmap
Portability: we export your data as JSON within 5 business days
Children's data
Cowork Recon is B2B-only. We do not knowingly collect data from
anyone under 18.
Security incidents
In the event of suspected unauthorized access to your data, we
notify your primary contact within 72 hours of discovery with a
written summary of scope and remediation.
Regulatory posture
Cowork Recon processes Nonpublic Personal Information (NPI) on
behalf of state-licensed insurance agencies. We act as a
service provider under the
GLBA
Safeguards Rule (16 CFR Part 314); the pilot agency remains the
data controller. A written information security program (WISP)
covering qualified-individual designation, risk assessment, access
control, encryption, sub-processor oversight, incident response, and
annual self-attestation is maintained per §314.4. The WISP
(version 1.0, last reviewed 2026-06-09) is available on request via
info@coworkrecon.com;
expect a copy within one business day. Where agencies are subject to
state-specific insurance data laws (NY DFS 23 NYCRR Part 500,
California Insurance Code data regulations, etc.), we cooperate with
documentation reasonably required for the agency's own compliance.
Certifications
We do not currently hold SOC 2 Type I or Type II.
SOC 2 Type I is targeted within 6 months of reaching 10 paying
customers. Agencies that require SOC 2 today should consider this a
known gap.
Changes
We update this policy when controls change. Material changes
notified by email; minor changes published here with the effective
date updated.