Skip to main content
PolicyChecked

Security

Built around private documents and limited access

Insurance documents contain private business information. This page describes how PolicyChecked is designed to handle them.

  • Private document storage

    Files are stored in a private storage bucket. There are no public file links, and files cannot be opened by guessing an address.

  • Authenticated accounts

    You sign in with a verified email address. Document upload and review requests require a verified account.

  • Access controls

    Database rules limit each customer to their own records. Staff access is limited by role and organization, and checked on the server.

  • Audit logging

    Sensitive actions, such as document views, downloads, and summary approvals, are recorded in an audit log.

  • Checked uploads

    Only PDF, JPG, and PNG files are accepted. File type and size are checked on the server before a file is accepted.

  • Short-lived download links

    When an authorized person opens a document, a link is created that expires within minutes, and the access is logged.

The secure upload process

  1. You sign in and verify your email address.
  2. You confirm you are authorized to share the document and consent to its processing.
  3. Our server checks the file type and size, and creates a new private storage location for it. You cannot choose or see that location.
  4. The file is uploaded directly to private storage and checked again on the server.
  5. The document waits for review by an authorized person. Every view and download is logged.

What we ask of you

  • Use a strong, unique password and keep it private.
  • Only upload documents you are authorized to share. Do not upload Social Security numbers, bank account numbers, or medical records.
  • Do not send documents or policy numbers through the contact form or by text message.
  • If you think someone else has accessed your account, change your password and contact us.