
The questionnaire in the order IT and GRC work through it, and what a good answer looks like.

Security review is the second thing that stops a claims AI deal, after accuracy, and the questionnaire barely changes between carriers. This is the list in the order an IT and GRC team works through it, with what a good answer looks like and where the published answers sit.
Security review is the second thing that stops a claims AI deal, after accuracy. The questions are not obscure, and they barely change between carriers.
This is the list, in the order an IT and GRC team usually works through it. Each question has a short answer explaining what a good response looks like, and where to find the vendor's actual position.
Run it on any vendor, including this one. The published answers below sit in the trust center and the security FAQ. A vendor that cannot point you at an equivalent page is asking you to take the answers on trust.
This is first because it is binding. Data residency is often a contractual or regulatory requirement, not a preference.
A good answer names the cloud provider, the specific regions, and whether the customer chooses. The trust center states that customers can choose between US or EU data centres. The security FAQ says processing and storage happen "either in Switzerland, in Germany or in another country of the customers choice", on AWS.
Ask where backups and logs live too. They frequently sit in a different region from the primary data, and that is where residency commitments quietly break.
Expect named algorithms and versions, not the word "encrypted".
The security FAQ states that "All data at rest is encrypted with the industry-standard AES-256" and that TLS 1.2 or higher protects data in transit. It also describes a bring-your-own-key option, with client-side encryption before transfer.
This question has a regulatory backdrop. The HIPAA Security Rule at 45 CFR 164.312 treats encryption as an addressable implementation specification, not a flat requirement. Addressable does not mean optional. It means the covered entity must assess it and document the decision.
Ask for the report, not the badge. A logo on a website is not an attestation.
The published trust center states SOC 2 Type II and ISO 27001. The underlying criteria are the AICPA's 2017 Trust Services Criteria, issued by the Assurance Services Executive Committee, covering security, availability, processing integrity, confidentiality and privacy.
Three follow-ups separate a real answer from a marketing one. Which trust services categories are in scope? What is the report period? And were there exceptions?
A Type II report covers a period of operating effectiveness. A Type I covers design at a point in time. They are not interchangeable, and vendors sometimes let the distinction blur.
This is the question most likely to be answered vaguely, and the one your legal team will care about most.
Get it in writing, in the contract, not in a sales email. The answer needs to cover three separate things: training, fine-tuning, and human review of inputs or outputs for quality purposes.
A vendor that uses a third-party foundation model must also state what that provider does with the data. Your contract is with the vendor; the exposure may sit one layer down.
If the published material does not address this, treat that as an open item rather than an implied no.
A subprocessor is any third party the vendor passes your data to. Every SaaS platform has them: cloud hosting, identity, email, analytics, monitoring.
The security FAQ names AWS for infrastructure, Auth0 for identity, and Clarity and Mixpanel for analytics on anonymised data. Ask for the complete current list as a contractual artefact, plus a notification commitment when it changes.
The notification term is the part that gets skipped. A subprocessor list without a change-notice clause tells you about today only.
Multi-tenant is normal. Undocumented multi-tenancy is not.
The security FAQ describes "Strong Tenant Isolation" with logical separation, customer-specific encryption keys and tenant-authorised requests, on a multi-tenant microservice architecture.
Ask how isolation is tested rather than how it is designed. Design documents describe intent; test results describe behaviour.
Your identity team will want the platform inside your existing identity provider, not beside it.
The trust center lists SAML single sign-on, enforced two-factor authentication, and SCIM controls for automated user provisioning. The security FAQ adds Auth0 as the identity layer, with optional integration of the customer's own identity provider. It also lists multi-factor authentication, bot detection and brute-force protection.
SCIM matters more than it looks. Without automated provisioning, deprovisioning depends on someone remembering, and leavers keep access.
Ask this during procurement, because it is unnegotiable afterwards.
Three things need to be specified: the export format, the deletion timetable including backups, and who confirms deletion in writing.
The security FAQ notes contractual provisions for data return. It also states that original documents stay in the customer's primary system, with metadata and annotations transferable at any time. Get the deletion side written down with the same specificity.
These belong in the contract, not in a slide.
The security FAQ states daily automated backups, with "Amazon RDS snapshots are retained for 30 days". It gives a recovery point and recovery time objective of one day each. It also describes multi-availability-zone AWS deployment, with automated failover in 60 to 120 seconds.
Then ask the harder question. When was the restore last tested end to end, and what was the result?
Claim files contain medical records, so this question is unavoidable in a bodily injury context.
The standard sets the floor. 45 CFR 164.312 requires technical policies allowing access "only to those persons or software programs that have been granted access rights". It also requires unique user identification, integrity protection and transmission security. Audit controls must "record and examine activity in information systems".
Each vendor's own position on PHI is a contractual question, and the trust center states it. Read that statement carefully against what the product actually does with records. A platform built for bodily injury claim file review handles medical documents by design. The PHI wording and the product scope need to line up. Then read both against your counsel's view of whether a business associate agreement is required.
Detection and notification are separate commitments. Vendors often describe the first and leave the second vague.
The security FAQ describes monitoring for unauthorised access, login monitoring, and alerting and escalation with customer notification. What you need in the contract is a defined notification window, measured in hours, and a named contact on both sides.
Ask who declares an incident. If only the vendor can, your notification clock starts when they decide it should.
Ask for breach history too. A vendor with none should say so plainly, and a vendor with one should be able to describe what changed afterwards.
This is the question that determines whether the deal survives your second-line review.
The NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers was adopted on 4 December 2023. Under it, oversight of third parties acting for the insurer is an insurer obligation. The bulletin "advises insurers of documentation that a state Department of Insurance may request during an investigation or examination."
So the vendor's evidence has to be good enough for your examiner, not just for your security team. Ask for four things:
The reason this list repeats across deals is that the answers usually live in a sales deck, and decks go stale.
Published answers in one place do three things. The buyer self-serves the first pass. The sales team stops rewriting the same document. And the version everyone is quoting is the current one.
Where a page like a trust center exists, send the questionnaire there first and handle only the gaps by email. Where it does not, expect the review to take weeks longer, whatever the product does.
Most of the twelve can be satisfied by a published page. Three cannot, and they are the ones to put in the contract.
A vendor that answers all three plainly has usually been through this review before. That is worth more than any certification logo.