Skip to content
Policy MitraAIOS

Security architecture

Policy Mitra AIOS is built so that each person sees only the records their role allows, and so that changes to those records leave a trace.

1. Secure by Design

Security is part of how the product is structured rather than a feature added on top. Records are organised around the relationship between a customer, their advisor and, where there is one, the advisor's brokerage. Access follows that relationship.

2. Role-based access

Every account has one role, and the role decides what can be opened:

  • Customers see their own policies, family members, documents, claims and requests.
  • Advisors see the customers assigned to them and those customers' records.
  • Brokers see the advisors in their organisation and the records those advisors manage.
  • Administrators manage accounts, the product catalogue and platform settings.

3. Activity history

Actions that change a record — adding a policy, uploading or verifying a document, updating a request or claim, reassigning a customer — are written to an activity history with the person and the time. Brokers and administrators can review and export it.

4. Documents

Each document is linked to a customer and, where relevant, to a policy or claim, and carries a status: requested, pending review, verified or rejected. Documents are visible to the policyholder, their assigned advisor and the brokerage that manages them.

5. Accounts

Accounts are protected by a password chosen by the user. Suspended accounts cannot sign in. Advisors who leave a brokerage can be made inactive, which removes their access while keeping the customer records with the brokerage.

6. Current status of the web application

The web application on this site currently runs as a demo workspace. It opens with sample data, and anything entered is stored in the visitor's own browser rather than on a server. In the demo, role checks are performed in the browser. Do not enter real customer information into the demo.

Policy Mitra does not currently claim any third-party security certification or audit. When independent assessments are completed, they will be listed on this page.

7. Reporting a concern

If you believe you have found a security problem, write to the support address in the footer of this site. Please do not share the details publicly until we have replied.

Related

Questions: Support@Policymitra.online