Security and document handling

Built for sensitive broker work.

Advanced Underwriters protects broker documents with encrypted connections, encrypted storage, workspace access controls, and scheduled data cleanup.

Transport

TLS in transit

Encrypts files while they move

Storage

AES-256 at rest

Protects stored broker files

Access

Workspace role checks

Limits access by organization and role

Retention

30-day sensitive-data retention

Scheduled cleanup

Document lifecycle

Security follows each file through the workflow.

Protection starts when a file is uploaded and continues through review, use, and scheduled cleanup.

01 · Upload

Check files before they enter the workspace.

Brokers confirm authorization and removal of unnecessary personal information before selected files leave the browser. Files then travel over TLS, remain tied to the active upload session, and are validated before entering the workspace.

02 · Review

Provide file access only when it is needed.

Authorized bearer links open source files only after an access request is approved and recorded. Each signed link expires 15 minutes after issuance.

03 · Work

Keep work inside the right organization.

Workspace roles control who can review files, compare programs, and create deliverables.

04 · Retention

Remove sensitive data on schedule.

Sensitive source files and related review data follow a 30-day cleanup schedule.

Verified controls

Security controls, explained clearly.

These are the protections in place for the current broker workflow.

Transport

TLS in transit

TLS encrypts broker files and application data while they move between the browser and the service.

Storage

Cloudflare-managed AES-256 at rest

Private broker files are stored in Cloudflare R2 with Cloudflare-managed AES-256 encryption at rest.

Authentication

Verified email/password through Clerk

Clerk owns verified email/password sign-in and session management.

Brokerage MFA

Available and strongly recommended

MFA is available and strongly recommended for brokerage workspace users.

Platform administration

MFA required

Advanced Underwriters requires MFA for platform administrators.

Access

Workspace role checks

Workspace membership and roles control access to client records and protected actions.

File upload

Upload session checks

Each upload is tied to the active session and checked before the file enters the workspace.

File access

Authorized bearer links

Signed links are created only after authorization, expire 15 minutes after issuance, and are not stored as application records. They remain bearer credentials until expiry.

Access records

Recorded file-access requests

Requests to open protected source files are recorded without saving the signed link itself.

How source review uses AI

Raw source documents are not sent to an external AI provider during standard source review.

Standard source review reads PDFs and spreadsheets, links values to their source, and keeps the broker in control. External AI is not required for this process.

During standard source review, raw documents are not sent to external AI providers.

Files are uploaded to Advanced Underwriters for parsing and review. The application stores and displays them so brokers can confirm the source.

  • External AI is not required for standard source review
  • Evidence and broker review remain visible
  • Organization access boundaries still apply

File access and retention

Authorize file access and limit how long sensitive data remains available.

Source-file access requests are authorized and recorded. Signed bearer links expire 15 minutes after issuance, and sensitive data follows a scheduled 30-day cleanup process.

30-day retention

Sensitive data is removed on schedule.

Source files and related review data are scheduled for cleanup after 30 days.

Bearer file access

File links are created only when needed.

The application does not save issued links as records. Each link expires 15 minutes after issuance and must not be shared while valid.

Recorded access

Source-file access requests are recorded.

The application records requests for protected source files so they can be reviewed.

Broker file questions

Broker file security FAQ

Clear answers about authorized real-document use, access, retention, and the limits of the current pilot.

Can I use real broker files?

Authorized broker documents can be used in a controlled pilot. Confirm that your organization and client permit processing, then remove personal information that is not needed before upload.

Where are uploaded files stored?

In production, private Cloudflare R2 storage holds source files and generated artifacts. TLS protects data in transit, and Cloudflare-managed AES-256 encryption protects data at rest. Convex remains the application-data and authorization provider.

Who can access a file?

Only authorized members of the organization who pass server-side role and ownership checks. Signed bearer links expire 15 minutes after issuance, are not saved as application records, and must not be shared while valid.

How long are files retained?

Sensitive source and review data follows a 30-day retention and cleanup schedule. Removing a source ends application access immediately; physical deletion is queued, while limited non-sensitive audit metadata may remain.

Is MFA required?

Authenticator-app MFA is strongly recommended for brokerage workspace users and required for platform administrators. SMS sign-in and MFA are disabled.

Are files sent to AI providers?

Raw documents are not sent to external AI providers during standard source review. The default pilot path uses source-backed review without requiring external AI.

What should not be uploaded?

Do not upload documents you are not authorized to process. Remove unnecessary Social Security numbers, dates of birth, license numbers, bank details, medical information, and similar personal data before upload. This pilot is not represented as SOC 2 certified, HIPAA compliant, end-to-end encrypted, formally penetration tested, or malware-scanned.

Questions about security?

Review the controls with us.

Read the vendor-ready summary or contact us to discuss document handling, access controls, and retention.

Read vendor reviewsales@advancedunderwriters.app