The most sensitive file in the building, treated like your own.
An insurance claim is a person's medical history, finances and worst year, in 800 to 2,400 pages. Owl reads it inside your perimeter, encrypts it end to end, cites every answer back to the page, and never uses it to train a shared model.
Our Security Principles
In addition to our array of certifications and affirmations, our unwavering commitment to upholding the highest security standards is evident through our strict adherence to the guidelines established by esteemed organizations such as the National Institute of Standards and Technology (NIST), Center for Internet Security (CIS), and International Organization for Standardization (ISO).
Confidentiality
We prioritize information security with encryption for data at rest and in transit. Our data union adheres to FIPS 140-2 encryption standards and maintains 24/7 monitoring for vulnerabilities and malware. We enforce time-based access controls to limit internal access to critical tools and resources.
Encryption
All data is encrypted with TLS in transit and AES-256 at rest. Keys are managed per tenant, and the most sensitive file in the building is held to the standard we would want for our own medical records.
Isolation
Customer claim files are never used to train shared models. Any style or domain calibration runs inside your tenancy, on your data, for your benefit. This is contractually enforced, not a default we can quietly change.
Returned or destroyed on offboarding.
Data is not retained beyond the contracted period. On offboarding it is returned or destroyed to your specification, with written confirmation.
Access controls
Access is role-scoped and granted on a least-privilege basis. Production access is restricted, reviewed, and revoked when it is no longer required.
Audit logs
Every page accessed and every answer produced is logged. Each extracted value and every output is auditable back to its source page, so a reviewer or a regulator can reconstruct exactly what was read and when.
The Foundation of Owl AI’s Protection
Data Encryption & Privacy
- —End-to-end encryption safeguards all data in transit and at rest.
- —Zero-trust architecture, only authorized users can access information.
- —Strict data anonymization protects identities and claim details.
Compliance & Regulations
- —Fully compliant with GDPR, HIPAA, SOC 2, ISO 27001, NAIC.
- —Built-in audit trails ensure full transparency and accountability.
- —AI models designed to meet legal and ethical standards.
Threat Detection & Prevention
- —Auto Anomaly detection identifies fraudulent activities in real time.
- —Continuous monitoring & automated alerts to prevent breaches.
- —Integration with industry security frameworks for risk management.
Access Control & Governance
- —Role-based access ensures data is only available to authorized users.
- —Multi-factor authentication (MFA) verification for extra protection.
- —Full audit logging & tracking to maintain compliance.
The model is accountable for what it says, and never for the decision.
Security is not only about who can reach the file. It is about whether you can trust what the system says about it, and who answers for the call that follows.
Every output is span-grounded.
No claim about a file leaves Owl without a verbatim citation back to the page. Span-grounded decoding is enforced at the model level, not as a UI affordance. If we cannot cite it, we will not say it.
AI never denies a claim.
Owl never makes the adverse decision. Adverse determinations require a licensed human reviewer and a written rationale. Our software surfaces the evidence, supports the decision and audits the outcome. It does not issue the denial.
Audited for disparate impact before release.
Every Owl model is audited across protected attributes against a pre-registered threshold before it ships. A failed audit blocks the release.
Owl-Bench is published and externally graded.
We publish the benchmark, invite the scrutiny, and let board-certified physicians and FCAS Fellows grade the models in public. External scrutiny is treated as a feature, not a risk.
Assessed against the frameworks your auditors already use.
Owl's security program is assessed against SOC 2 Type II, HIPAA and ISO 27001, with standard GDPR and CCPA handling where applicable.
Found something? Tell us, and we will tell you what we did about it.
We welcome reports from security researchers and treat them as help, not as a threat.
Email security@owl.co with the details. We acknowledge reports within two business days and aim to confirm a fix or a mitigation within 90 days, coordinating the disclosure window with you. Our policy and contact key are published at owl.co/.well-known/security.txt. Please do not access claimant data, degrade service, or test against production tenants while researching.
Bring your security team. We built this page so they would not have to ask twice.
Request our security posture, SOC 2 report under NDA, or a review with our security team.