Skip to main content
Home›Platform › Security and Permissions
Enterprise Security

Enterprise-Grade Security and Role-Based Permissions for Insurance Claims

Every user sees what they should. Nothing more.

ECode Pro protects sensitive claims data with AES-256 encryption, role-based access controls, complete audit logging, and a permission architecture designed for the compliance requirements of regulated insurance organizations.

Book a Free Demo → Talk to Our Team
Security Dashboard
Active Users
47 authenticated
Permission Roles
8 configured
Audit Events Today
1,247
Failed Logins
0 in 30 days
Recent Activity
System
SOC 2 Type II audit completed
This quarter
Access
2 new role permissions configured
Yesterday
Audit
Complete access log exported — Q4
2 days ago
Security
All data encrypted at rest — AES-256
Always active
The Problem

Insurance Claims Data Is Among the Most Sensitive Information Your Organization Handles

Personal information, medical records, financial data, and legal communications all live in your claims files. A data breach involving claims data creates regulatory exposure, litigation risk, and reputational damage that can end an organization. Yet most claims software treats security as an afterthought — a password and a basic login screen.

The regulatory environment for insurance data is complex and increasingly strict. State insurance departments have detailed requirements for data security. The NAIC Model Law on cybersecurity sets minimum standards that most states have adopted. HIPAA applies to any claim involving health information. SOC 2 compliance is increasingly required by carrier clients before they will authorize a TPA or IA firm to handle their claims.

ECode Pro was built with security architecture that meets these requirements — not as an add-on, but as a foundation. Every piece of data is encrypted. Every access is logged. Every permission is defined and enforced. And every change to the system is recorded with an immutable audit trail.

Without ECode Pro

Claims data accessible to anyone with a system login rather than role-appropriate access
No systematic audit trail of who accessed which claims and when
Carrier clients unable to provide read-only access without giving full system access
No documented security architecture for carrier or regulatory review
User permissions managed informally rather than through a defined role structure
With ECode Pro: Every access controlled. Every action logged. Every audit request answered in minutes.
Everything Included

Every Feature You Need

No add-ons. No hidden tiers. Included with every ECode Pro subscription.

AES-256 Encryption at Rest

Every claim file, document, note, payment record, and personal data point stored in ECode Pro is encrypted with AES-256 — the same standard used by financial institutions and government agencies. Data at rest is never stored in plain text.

TLS 1.3 Encryption in Transit

All data transmitted between ECode Pro and its users travels over TLS 1.3 encrypted connections. Unsecured connections are rejected. Certificate management is handled by ECode Pro infrastructure with automatic renewal.

Role-Based Access Controls

Access in ECode Pro is defined by role — what each user can see, edit, approve, and report on. Roles are configured by your administrators and enforced at the application level. An adjuster cannot access claims outside their queue. A carrier cannot see another carrier's data.

Complete Immutable Audit Log

Every action taken in ECode Pro — every view, edit, approval, payment, and login — is recorded in an immutable audit log with the user identity, timestamp, IP address, and action taken. Audit logs cannot be modified or deleted by any user, including administrators.

Multi-Factor Authentication

ECode Pro supports multi-factor authentication for all user accounts. MFA can be required by role — all supervisors require MFA, for example — or by organization policy. Supported methods include authenticator app, SMS, and hardware token.

SOC 2 Type II Compliance Documentation

ECode Pro maintains SOC 2 Type II compliance documentation available to enterprise customers, carriers, and regulatory examiners on request. Our controls cover security, availability, processing integrity, confidentiality, and privacy.

Our new carrier partner required SOC 2 documentation and a security review before approving us as a vendor. ECode Pro had everything we needed ready to share. The carrier said it was the most complete security package they had received from a TPA.

Rebecca H.
COO
Customer Result

Security Documentation That Satisfies Carriers and Regulators

SOC 2 Type II documentation available for carrier vendor approval processes
Role-based permissions prevent unauthorized access to sensitive claim data
Complete audit trail satisfies regulatory examination requirements in all jurisdictions
Carrier data isolation verified at architecture level — not policy level
Zero data breach incidents across all ECode Pro customers
See How It Works →

Frequently Asked Questions

Common questions before your demo.

Yes. ECode Pro maintains SOC 2 Type II compliance. Our audit report and controls documentation are available to enterprise customers and carrier partners for vendor approval processes on request.
Permissions are defined by role. Standard roles include Owner, Director, Claims Manager, Team Lead, Desk Adjuster, Field Adjuster, Carrier Viewer, and Vendor. Each role has a defined permission set. Roles can be customized by your administrators within your organization.
Yes. MFA can be required for all users, for specific roles, or as an optional setting per user. We recommend requiring MFA for all supervisor and above roles at minimum.
We provide a full data export in standard formats before account closure. After the export is confirmed, data is purged from our systems within 30 days and we provide written confirmation of deletion.

See ECode Pro Security Documentation

Book a demo and we will walk through our security architecture, compliance documentation, and permission controls.

Book a Free Demo →