Proxaradocs
Trust Center/Compliance

Security Overview

The private environment provisioned for one brokerage: where account data is processed, what the local models see, how credentials stay outside model context, what the evidence record holds, encryption, retention, and exit.

Updated September 2026

Security Overview

Last updated: September 3, 2026

This document describes the private environment Proxara provisions for a commercial insurance brokerage, for the person who reviews security before a pilot. It states what the product does; the signed agreement and order form fix the details for a given brokerage.

1. One environment per brokerage

Each brokerage runs in its own dedicated cloud environment, provisioned in the region the brokerage chooses. Compute, storage, model serving, keys and credentials are never shared between customers. The environment is operated by Proxara; the brokerage's data belongs to the brokerage.

2. Where the evidence lives

Proxara reads the brokerage's evidence where it already lives: mailboxes and files in Microsoft 365, the agency management system, carrier channels and downloads, document stores. Each connection is limited to the mailboxes, records and actions the brokerage authorises, under the brokerage's own access. The environment holds what it derives from that evidence, with every value attributed to its source and the time it became known. It does not hold a standing copy of the book, and it is never the system of record.

3. Local models

The models that read documents, emails and carrier records run inside the environment. No account data is sent to an external AI service. What the models learn from the brokerage's corrections and from each policy that issues stays inside that brokerage's environment and never trains a model used by anyone else.

4. Credentials and execution

The credentials that act on the brokerage's systems live in the execution boundary, outside anything a model can read. A model proposes; only the execution boundary performs, and it performs each action exactly once, with a retry recovering the same action rather than creating a second one.

5. Authority and approvals

The brokerage sets, for each kind of work, whether it may proceed on its own, proceed and report, or wait for a named person. Approvals arrive in Microsoft Teams as one bounded release with the evidence and the exact action attached. An approval covers exactly the action that was shown; if the evidence around it changes, the release is withdrawn and presented again. Coverage judgment, market strategy and binding are always a named person's decision.

6. The record

Every action closes against five things: the evidence it started from, the meaning resolved from it, the authority it ran under, the exact payload that left, and the proof the receiving system returned. Any account or event exports as a signed evidence package.

7. Encryption and access

Data is encrypted in transit and at rest. Client identities are individually keyed, so a single identity can be erased by destroying its key. Proxara personnel hold no standing access to a brokerage's environment; privileged access for support is time-bound and recorded.

8. What Proxara receives

Operational counts, codes and health signals from the environment, enough to run it: what kind of work ran, whether it completed, which systems were reached and whether they answered. Not what was read, not what was asked, and no client name.

9. Retention and exit

Derived state, the evidence record and learned adjustments remain in the environment for the term of the agreement. On exit the brokerage receives its evidence record as signed packages, after which the environment and its keys are destroyed.

10. Reporting a concern

security@proxara.ai. We acknowledge reports within two business days.