Transport
Security and document handling
Built for sensitive broker work.
Advanced Underwriters protects broker documents with encrypted connections, encrypted storage, workspace access controls, and scheduled data cleanup.
Storage
AES-256 at rest
Protects stored broker filesAccess
Workspace role checks
Limits access by organization and roleRetention
30-day sensitive-data retention
Scheduled cleanupDocument lifecycle
Security follows each file through the workflow.
Protection starts when a file is uploaded and continues through review, use, and scheduled cleanup.
01 · Upload
Check files before they enter the workspace.
Brokers confirm authorization and removal of unnecessary personal information before selected files leave the browser. Files then travel over TLS, remain tied to the active upload session, and are validated before entering the workspace.02 · Review
Provide file access only when it is needed.
Authorized bearer links open source files only after an access request is approved and recorded. Each signed link expires 15 minutes after issuance.03 · Work
Keep work inside the right organization.
Workspace roles control who can review files, compare programs, and create deliverables.04 · Retention
Remove sensitive data on schedule.
Sensitive source files and related review data follow a 30-day cleanup schedule.Verified controls
Security controls, explained clearly.
These are the protections in place for the current broker workflow.
Transport
TLS in transit
TLS encrypts broker files and application data while they move between the browser and the service.Storage
Cloudflare-managed AES-256 at rest
Private broker files are stored in Cloudflare R2 with Cloudflare-managed AES-256 encryption at rest.Authentication
Verified email/password through Clerk
Clerk owns verified email/password sign-in and session management.Brokerage MFA
Available and strongly recommended
MFA is available and strongly recommended for brokerage workspace users.Platform administration
MFA required
Advanced Underwriters requires MFA for platform administrators.Access
Workspace role checks
Workspace membership and roles control access to client records and protected actions.File upload
Upload session checks
Each upload is tied to the active session and checked before the file enters the workspace.File access
Authorized bearer links
Signed links are created only after authorization, expire 15 minutes after issuance, and are not stored as application records. They remain bearer credentials until expiry.Access records
Recorded file-access requests
Requests to open protected source files are recorded without saving the signed link itself.How source review uses AI
Raw source documents are not sent to an external AI provider during standard source review.
Standard source review reads PDFs and spreadsheets, links values to their source, and keeps the broker in control. External AI is not required for this process.
During standard source review, raw documents are not sent to external AI providers.
Files are uploaded to Advanced Underwriters for parsing and review. The application stores and displays them so brokers can confirm the source.
- External AI is not required for standard source review
- Evidence and broker review remain visible
- Organization access boundaries still apply
File access and retention
Authorize file access and limit how long sensitive data remains available.
Source-file access requests are authorized and recorded. Signed bearer links expire 15 minutes after issuance, and sensitive data follows a scheduled 30-day cleanup process.
30-day retention
Sensitive data is removed on schedule.
Source files and related review data are scheduled for cleanup after 30 days.Bearer file access
File links are created only when needed.
The application does not save issued links as records. Each link expires 15 minutes after issuance and must not be shared while valid.Recorded access
Source-file access requests are recorded.
The application records requests for protected source files so they can be reviewed.Broker file questions
Broker file security FAQ
Clear answers about authorized real-document use, access, retention, and the limits of the current pilot.
Can I use real broker files?
Authorized broker documents can be used in a controlled pilot. Confirm that your organization and client permit processing, then remove personal information that is not needed before upload.
Where are uploaded files stored?
In production, private Cloudflare R2 storage holds source files and generated artifacts. TLS protects data in transit, and Cloudflare-managed AES-256 encryption protects data at rest. Convex remains the application-data and authorization provider.
Who can access a file?
Only authorized members of the organization who pass server-side role and ownership checks. Signed bearer links expire 15 minutes after issuance, are not saved as application records, and must not be shared while valid.
How long are files retained?
Sensitive source and review data follows a 30-day retention and cleanup schedule. Removing a source ends application access immediately; physical deletion is queued, while limited non-sensitive audit metadata may remain.
Is MFA required?
Authenticator-app MFA is strongly recommended for brokerage workspace users and required for platform administrators. SMS sign-in and MFA are disabled.
Are files sent to AI providers?
Raw documents are not sent to external AI providers during standard source review. The default pilot path uses source-backed review without requiring external AI.
What should not be uploaded?
Do not upload documents you are not authorized to process. Remove unnecessary Social Security numbers, dates of birth, license numbers, bank details, medical information, and similar personal data before upload. This pilot is not represented as SOC 2 certified, HIPAA compliant, end-to-end encrypted, formally penetration tested, or malware-scanned.
Questions about security?
Review the controls with us.
Read the vendor-ready summary or contact us to discuss document handling, access controls, and retention.
