AI governance for carriers, MGAs, and TPAs.
GLBA, NAIC Model Law, CCPA, and SOX compliance bundles active simultaneously. Policyholder NPI blocked before it reaches any model. Claims data stays in your environment. Examiner-ready audit logs from day one.
Compliance built for insurance data environments.
GLBA Safeguards Rule — Annuity and Life Product NPI
Insurance products subject to GLBA — annuities, credit life, mortgage protection — require NPI handling controls for policyholder financial information. Arbitex detects NPI across every AI interaction: account numbers, SSNs, tax IDs, beneficiary data, and annuity contract terms. Access controls are enforced by team and role. Every NPI access is logged with user context, policy version, and enforcement action — providing the documentation trail the Gramm-Leach-Bliley Safeguards Rule requires.
Policyholder PII Across All 50 States
Insurance regulation is state-by-state — CCPA in California, NY SHIELD Act in New York, and state privacy laws in every jurisdiction you operate in. Arbitex compliance bundles map to the NAIC Insurance Data Security Model Law and state-level NPI handling requirements simultaneously. One policy configuration governs AI access to policyholder names, addresses, medical histories, claim records, and financial data — enforced in-path before any language model processes the request.
AI Governance for Underwriting Models
AI-assisted underwriting introduces model risk: biased training data, unexplainable decisions, and regulatory scrutiny under NAIC guidance on AI use in insurance. Arbitex creates an auditable record of every AI query in the underwriting workflow — who asked, what the model received, what it returned, and what action was taken. No applicant data transits the Arbitex cloud; the data plane runs inside your environment. The audit trail supports internal model governance reviews and state regulatory inquiries.
Claims Data Sovereignty — Hybrid Outpost
Claims files contain medical records, legal correspondence, fraud investigation notes, and financial settlements — all subject to strict data handling requirements. Arbitex Hybrid Outpost deploys the data plane inside your VPC using Docker Compose or Kubernetes. Claims data, adjuster notes, and litigation records never transit Arbitex-controlled infrastructure. The control plane handles configuration and policy; your data stays in your environment. Compliance obligations follow the data, not the network path.
Examiner-Ready Audit Logs
State insurance department examinations require documented evidence of AI data handling controls. Every AI enforcement action is written to an tamper-proof, append-only audit log. No user — including administrators — can modify or delete records. Signed exports are available in CSV and JSONL for examination requests. Retention is configurable to meet state record-keeping requirements. The audit log surfaces in the admin portal for internal compliance reviews between examinations.
SOX IT Controls for Holding Company Structures
Insurance holding companies with publicly-traded parents face SOX Section 404 IT control requirements for AI systems supporting financial reporting. Arbitex enforces access controls by role for AI supporting reserving, loss development, and financial close workflows. Every policy configuration change is version-logged with before/after deltas — providing a tamper-evident record for SOX IT audit submissions and external auditor review.
How it works
Deploy inside your claims environment
The Arbitex data plane installs in your cloud environment using Docker Compose or Kubernetes. All AI traffic — claims adjuster queries, underwriting requests, customer service interactions — routes through it before reaching any model. DLP inspection, policy enforcement, and audit logging run inside your infrastructure. Claims data, medical records, and policyholder information never leave your environment.
Activate insurance compliance bundles
Apply pre-built compliance bundles for GLBA, NAIC Model Law, CCPA, and SOX. All bundles are active simultaneously under one policy configuration. Detection rules cover NPI, policy identifiers, medical record numbers, SSNs, and financial account data. Enforcement actions (block, redact, flag) and access controls are configured by team and workflow. Every configuration change is version-logged with a tamper-evident before/after delta.
Every AI interaction inspected and logged
From the first call, every AI request and response passes through the detection pipeline. NPI, claims data, and policyholder identifiers are enforced per policy before any model processes the content. The tamper-proof audit log captures the complete record — available for state insurance examination requests, internal compliance reviews, and SOX IT audit submissions.
Six frameworks. One policy layer.
Each compliance obligation maps to a specific Arbitex capability. All bundles are active simultaneously — no separate configuration per framework or jurisdiction.
NPI detection and access controls for annuity, life, and mortgage-related insurance products. Every NPI access logged with user context and policy version.
State-level insurance data security compliance mapped to one policy configuration. Covers policyholder data, claims records, and producer information.
Consumer rights-aware data handling for California policyholders. PII detection in-path before AI model access. Configurable by geography and data category.
Private information protection for New York policyholders. Detection covers SSNs, financial account numbers, and health information — enforced in-path.
Access controls and version-logged configuration changes for AI supporting financial reporting in insurance holding company structures.
Audit documentation infrastructure for AI use in underwriting and claims — supports insurer filings and state regulatory inquiry responses.
Related Resources
AI adoption in insurance starts with data sovereignty.
Arbitex gives carriers, MGAs, and TPAs the governance layer to deploy AI in claims, underwriting, and customer service without creating policyholder data exposure. Every AI call inspected. Every AI call logged. Claims data never leaves your environment.