Annual billing saves 2 months free — and IUL Illustration Engine is now live. See plans →
Trust Center

Security at CoverAgent, Stated Plainly

How we host, protect and separate your agency's data, what we record as evidence, and where we stand on audits. If a control isn't listed here, we don't claim it. CoverAgent AI does not replace legal or compliance professionals.

Infrastructure

Where CoverAgent Runs

Google Cloud and Firebase

The CoverAgent web app runs on Google Cloud Run and the AI backend on Cloud Functions for Firebase, both deployed in Google's us-central1 (Iowa) region. Records are stored in Cloud Firestore and files in Cloud Storage for Firebase. Sign-in is handled by Firebase Authentication.

Encryption in transit and at rest

Traffic to the app is served over HTTPS (TLS), and the app sends a Strict-Transport-Security header so browsers keep using HTTPS. Google Cloud encrypts stored data at rest by default, using Google-managed keys.

Secrets and credentials

Production secrets such as payment and webhook keys are held in Google Secret Manager and injected at runtime, not committed to source code. Integration credentials that agencies connect (for example messaging-provider keys and calendar or social account tokens) are additionally encrypted by the application with AES-256-GCM before they are stored. Service API keys are stored only as SHA-256 hashes.

We don't currently offer a choice of data region or customer-managed encryption keys.

Tenant Separation

How Agencies Are Kept Apart

Separation is enforced at three layers: where data is stored, who the server lets in, and what the database allows.

One tenant path per agency

CoverAgent is a multi-tenant service: agencies share the same infrastructure, and separation between them is enforced in software. Each agency’s records are stored under its own tenant path.

Server-side authorization

Portal API routes resolve the tenant and the caller’s role from the signed-in session, not from anything the browser sends, and check the role before reading or writing.

Database rules deny by default

Firestore security rules deny browser access unless a rule allows it, and allow reads only to members of that tenant. Consent records, the touch ledger and the audit ledger cannot be read or written from the browser at all; only server code writes them.
Access Control

Roles, Re-authentication and Sign-in

Five workspace roles decide what each person can see and change.

RoleAccess
OwnerFull control of the agency workspace, billing and team.
AdminManages the workspace and team on the owner’s behalf.
ManagerTeam-scoped: sees records for the agents who report to them. Never escalated to admin.
ComplianceAgency-wide read access for review and oversight.
AgentWorks their own assigned leads, clients and tasks.

Step-up re-authentication

Sensitive operations, such as connecting insurance-provider accounts and editing producer mappings, ask you to re-enter your password or re-confirm your Google sign-in if you last signed in more than five minutes ago.

Not available yet

Two-factor authentication is not available yet. We do not offer single sign-on (SSO or SAML) yet. Sign-in is by email and password or Google sign-in.
Audit & Evidence

Records You Can Show an Auditor

Hash-chained audit ledger

Each agency has one audit chain. Every entry carries a sequence number, the previous entry’s hash and its own SHA-256 hash, so deleting, reordering or editing an entry breaks verification from that point on. That makes the ledger tamper-evident: changes can be detected, not prevented.

Consent records

Consent events are stored as append-only evidence, written only by server code, and checked before marketing messages are sent.

Dispatch touch ledger

Every outbound email and SMS decision is recorded, whether the message was sent or blocked, with a fixed reason code such as missing consent, opt-out, quiet hours or a frequency cap.

Retention by plan

We retain audit records per plan tier: 14 days on Starter, 90 days on Pro, 365 days on Agency, and the longest window on Enterprise (ask us for current terms). A formal retention schedule is in development.
Messaging Controls

Outreach Controls Built Into Every Send

CoverAgent provides workflow controls that help agencies manage TCPA-oriented consent and outreach practices. You remain responsible for how you obtain consent and what you send.

Consent gate

Marketing email and SMS pass through a single dispatch gate that requires a verified consent record and an active, published enrollment before anything is sent.

Opt-out handling

Replies of STOP, STOPALL, UNSUBSCRIBE, CANCEL, END or QUIT opt the number out of SMS. Opted-out and unsubscribed recipients are refused at the gate.

Quiet hours

Messages are held outside 8am–8pm in the recipient’s local time, for email and SMS alike. There is no bypass switch.

Frequency caps

Marketing messages are capped at one per rolling 24 hours and four per rolling 7 days per person, counted across every channel and sequence.

CAN-SPAM footer and one-click unsubscribe

Commercial email carries the sender’s postal address and an unsubscribe link, plus List-Unsubscribe headers for one-click unsubscribe (RFC 8058). Email is not sent if the sender has no postal address on file.

A2P 10DLC registration

SMS is sent through Twilio. Business texting to U.S. numbers over 10-digit long codes requires A2P 10DLC brand and campaign registration with the carriers, and the carriers decide approval and throughput.
Privacy

How We Handle Client Information

GLBA-oriented safeguards

CoverAgent includes controls that support GLBA-oriented data handling (encryption, access control, audit logging). They are designed to support your own Safeguards Rule obligations; they do not satisfy them for you.

AI and your data

We do not use your personal information to train public AI models. Details are in our privacy policy and AI disclosure.
Subprocessors

Third Parties That Process Data for Us

These are the providers integrated in the CoverAgent platform today, and what each is used for.

ProviderPurposeNotes
Google Cloud / FirebaseHosting (Cloud Run, Cloud Functions), database (Cloud Firestore), file storage, sign-in (Firebase Authentication) and secret storage (Secret Manager).us-central1 region for compute.
Google Gemini (Gemini API / Vertex AI)Primary AI model provider for assistant, coaching, drafting and classification features.—
AnthropicSecondary AI model provider, used as a failover when it is enabled in our configuration.—
StripeSubscription billing and payment processing.Card details are handled by Stripe.
ResendEmail delivery.Agencies can also connect their own Resend account.
TwilioSMS delivery and inbound SMS (including STOP opt-out replies).Agencies can also connect their own Twilio account.

Optional integrations you connect yourself, such as Google Calendar or Meta Ads, receive data only when you turn them on.

Compliance Status

Where We Stand on Audits

SOC 2

We have not yet completed a SOC 2 audit, and we hold no third-party security certifications or attestations. Our internal policy library maps our controls to the SOC 2 criteria; that is preparation work, not an audit. Contact us for our current security documentation.

Penetration testing

We have not yet completed a third-party penetration test. Contact us for our current security documentation.
Responsible Disclosure

Report a Security Issue

Found a vulnerability?

Email support@coveragent.ai with "Security report" in the subject, the steps to reproduce, and the impact you observed. Please give us reasonable time to fix the issue before disclosing it publicly, and don't access other customers' data while testing.

Need a DPA or a security questionnaire?

Ask through our enterprise contact form and tell us which documents your review needs.

Doing Vendor Due Diligence?

Request a DPA, a security questionnaire, or a walkthrough of these controls with our team.