Skip to main content
Trust & Enterprise Data Governance

Security, Privacy, and Actuarial Provenance

Underwriting California catastrophe risk requires uncompromising data privacy and regulatory compliance. VesperSpatial is architected from the bare metal up to satisfy the strictest Chief Risk Officer (CRO), Information Security, and treaty reinsurance standards.

Defense-In-Depth Architecture

Six Pillars of Carrier-Grade Security

Zero Data Retention for Audits

Ephemeral In-Memory Evaluation

When carrier and MGA partners provide anonymized address CSVs for 48-hour parallel scrubs, the data is evaluated exclusively within volatile, ephemeral container memory. Submission records are permanently wiped post-generation. Your policyholder data is never retained, never used to train public machine learning models, and never shared across tenants.

Military-Grade Cryptography

AES-256 & TLS 1.3 Everywhere

All data at rest is encrypted with AES-256-GCM hardware-accelerated encryption across Google Cloud SQL volumes, PostgreSQL 16 tables, and Cloudflare R2 backup storage. All communications in transit enforce modern TLS 1.3 with Perfect Forward Secrecy and strict HSTS headers.

Cryptographic Merkle Audit Trails

Immutable Underwriting Provenance

Every rating indication, corridor accumulation check, and new-bind freeze flag is anchored to a SHA-256 Merkle audit ledger (api_request_audit_logs). Decisions are verifiable and tamper-proof, providing non-repudiation for internal audit committees and CDI examinations.

Sovereign US-Only Cloud Hosting

Domestic Compute & Storage Boundaries

All production application servers, Redis caches, PostgreSQL database replicas, and spatial calculation pipelines reside strictly within the continental United States (Google Cloud Platform US-West and Cloudflare US Tier-1 edge). Zero data routes through foreign jurisdictions.

ASOP 38 Actuarial Standards

Certified Model Governance

The Delphi-1.0 physical catastrophe model adheres strictly to Actuarial Standard of Practice No. 38 (Catastrophe Modeling Governance) and California Insurance Code § 2644.9 (Safer from Wildfires). Every parameter change, calibration run, and science version is sealed with an immutable git SHA and provenance hash.

Strict Tenant Isolation

Row-Level Partitioning & ed25519 Keys

Carrier and MGA data is partitioned with strict multi-tenant boundaries at the database and API layer. Each partner receives dedicated ed25519 cryptographic keypairs, webhooks are HMAC-signed with SHA-256, and session authentication utilizes rotating JWT tokens with short expiry windows.

Vendor Onboarding & Legal Packet

Standard institutional agreements available for accelerated procurement and Chief Risk Officer sign-off.

Standard Mutual Non-Disclosure Agreement (M-NDA)

Two-way mutual trade secret and confidential data protection.

Request

6-Week Shadow Pilot Agreement (v1.1)

Zero-cost, zero-IT integration shadow parallel testing terms.

Apply

Occurrence Ops CUO Executive Brief (PDF)

2-page printable technical and operational brief for Chief Underwriting Officers.

Download PDF
Vulnerability Disclosure & Incident Response

We maintain an active vulnerability management program and welcome responsible disclosures from researchers and security engineers. If you identify a potential security issue on any VesperSpatial domain or API endpoint, please contact our security team immediately:

Email: [email protected]Response SLA: < 12 HoursSecurity Officer: Conner Kupferberg