Advanced security and compliance standards for modern insurance operations

Customer trust and data security is of the utmost importance to Akur8. We are committed to protecting your data by adopting the highest security standards.
Access our Trust Center
Afaq iso27001 logo
FSQS logo
AICPA SOC2 logo
ISO 27001-certified

Your data is protected by a best-in-class information security management system

Customer trust and data security is of the utmost importance to Akur8. We are committed to protecting your data by adopting the highest security standards.

SOC 2 Type II Report Available

Independently audited to the highest standards

Akur8's completion of the SOC 2 Type II audit demonstrates its commitment to maintaining high standards and continuously assessing the effectiveness of its data security measures. The SOC 2 report outlines the extensive security, availability, and confidentiality controls Akur8 has implemented and maintains to meet both internal requirements and customer expectations.

Cloud Computing

Rely on leading cloud infrastructure designed for resilience and continuous availability

Akur8 products run on leading cloud platforms engineered for high availability. The cloud platforms we build on operate under rigorous, independent compliance programs, including:
SOC 2 Type II, ISO 27001, ISO 27017, and ISO 27018

Data Security

Your data is safe with a platform secured by design

Security has been integrated from the beginning in the design and the development of the Akur8 platform to ensure the confidentiality, integrity and availability of your data.

Confidentiality

We implement a variety of controls to ensure your data remains confidential and is accessed only by authorized persons. These controls include, but are not limited to: strict isolation between customers, the encryption of data with state of the art algorithms, strict access controls and regular penetration tests by an independent third party.

Integrity

We deploy a variety of controls to ensure that your data is protected against unauthorized alterations, such as strict access controls, regular backups, regression tests in the change management process, audit trails, and more.

Availability

Our platform and your data are automatically replicated in several locations to ensure a high level of resilience and backups are performed on a daily basis.

Compliance Privacy Standards

Akur8 products do not require the use of any personal data (PII), only pseudonymized or fully anonymized datasets should be used.

Frequently Asked Questions

Does Akur8 have a dedicated security team?

Yes. Akur8 has a dedicated security team led by a Chief Information Security Officer (CISO). The team is responsible for designing, implementing, and overseeing the information security program across all Akur8 products.

How does Akur8 develop code securely?

Akur8 follows a structured software development lifecycle (SDLC) that ensures code is rigorously tested, authorized, and approved before reaching production. Changes go through defined review and approval stages, including peer code review and security testing, to maintain the integrity and security of the platform.

Is data encrypted at rest and in transit?

Yes. Data is encrypted at rest using AES-256 and in transit using TLS 1.2 or higher. All communication sessions between the platform and end-users are secured via HTTPS.

Does Akur8 conduct penetration testing?

Yes. An independent third party performs an application-level penetration test at least once a year. The penetration test attestation letter is available on request through our Trust Center.

How does Akur8 monitor for vulnerabilities?

Vulnerability scans run at least monthly across public-facing components, internal systems, and code repositories. A SIEM collects and analyzes logs in real time, alerting the security team to suspicious patterns. Continuous threat detection monitors production environments for unauthorized or malicious activity.

How is access to systems and data managed?

Access follows a role-based model (RBAC) with least-privilege principles. Multi-factor authentication (MFA) is enforced for remote and production access. User access is reviewed biannually to confirm it remains appropriate.

What happens if there is a security incident?

Akur8 maintains a documented incident response plan with defined escalation paths based on severity. Affected customers and relevant stakeholders are notified without undue delay and in accordance with contractual obligations and applicable regulation.

How does Akur8 ensure platform availability?

Akur8 products are built on leading cloud providers engineered for high availability. Data and services are replicated across multiple availability zones, ensuring continuity in the event of a localized failure. Backups run daily. Failover procedures and restore-from-backup processes are tested regularly as part of our Business Continuity and Disaster Recovery (BC/DR) program, and infrastructure is monitored continuously.

Are Akur8 employees trained on security?

Yes. All employees complete mandatory security awareness training at onboarding and at least annually thereafter. Developers receive additional secure development training based on the OWASP Top 10.

How does Akur8 manage third-party and vendor risk?

Akur8 maintains a third-party risk management process. Vendors and contractors are subject to contractual confidentiality and security requirements. Third parties are reviewed periodically, with a review cadence based on criticality and risk profile.

Can I get a copy of the SOC 2 Type II report?

Yes. SOC 2 Type II reports are available through the Akur8 Trust Center. Request access here.

All FAQ
Get in touch with our team to learn more about our security standards
Contact us