Skip to main content
Insurance

AI governance for carriers, MGAs, and TPAs.

GLBA, NAIC Model Law, CCPA, and SOX compliance bundles active simultaneously. Policyholder NPI blocked before it reaches any model. Claims data stays in your environment. Examiner-ready audit logs from day one.

Capabilities

Compliance built for insurance data environments.

GLBA Safeguards Rule — Annuity and Life Product NPI

Insurance products subject to GLBA — annuities, credit life, mortgage protection — require NPI handling controls for policyholder financial information. Arbitex detects NPI across every AI interaction: account numbers, SSNs, tax IDs, beneficiary data, and annuity contract terms. Access controls are enforced by team and role. Every NPI access is logged with user context, policy version, and enforcement action — providing the documentation trail the Gramm-Leach-Bliley Safeguards Rule requires.

Policyholder PII Across All 50 States

Insurance regulation is state-by-state — CCPA in California, NY SHIELD Act in New York, and state privacy laws in every jurisdiction you operate in. Arbitex compliance bundles map to the NAIC Insurance Data Security Model Law and state-level NPI handling requirements simultaneously. One policy configuration governs AI access to policyholder names, addresses, medical histories, claim records, and financial data — enforced in-path before any language model processes the request.

AI Governance for Underwriting Models

AI-assisted underwriting introduces model risk: biased training data, unexplainable decisions, and regulatory scrutiny under NAIC guidance on AI use in insurance. Arbitex creates an auditable record of every AI query in the underwriting workflow — who asked, what the model received, what it returned, and what action was taken. No applicant data transits the Arbitex cloud; the data plane runs inside your environment. The audit trail supports internal model governance reviews and state regulatory inquiries.

Claims Data Sovereignty — Hybrid Outpost

Claims files contain medical records, legal correspondence, fraud investigation notes, and financial settlements — all subject to strict data handling requirements. Arbitex Hybrid Outpost deploys the data plane inside your VPC using Docker Compose or Kubernetes. Claims data, adjuster notes, and litigation records never transit Arbitex-controlled infrastructure. The control plane handles configuration and policy; your data stays in your environment. Compliance obligations follow the data, not the network path.

Examiner-Ready Audit Logs

State insurance department examinations require documented evidence of AI data handling controls. Every AI enforcement action is written to an tamper-proof, append-only audit log. No user — including administrators — can modify or delete records. Signed exports are available in CSV and JSONL for examination requests. Retention is configurable to meet state record-keeping requirements. The audit log surfaces in the admin portal for internal compliance reviews between examinations.

SOX IT Controls for Holding Company Structures

Insurance holding companies with publicly-traded parents face SOX Section 404 IT control requirements for AI systems supporting financial reporting. Arbitex enforces access controls by role for AI supporting reserving, loss development, and financial close workflows. Every policy configuration change is version-logged with before/after deltas — providing a tamper-evident record for SOX IT audit submissions and external auditor review.

How it works

01

Deploy inside your claims environment

The Arbitex data plane installs in your cloud environment using Docker Compose or Kubernetes. All AI traffic — claims adjuster queries, underwriting requests, customer service interactions — routes through it before reaching any model. DLP inspection, policy enforcement, and audit logging run inside your infrastructure. Claims data, medical records, and policyholder information never leave your environment.

02

Activate insurance compliance bundles

Apply pre-built compliance bundles for GLBA, NAIC Model Law, CCPA, and SOX. All bundles are active simultaneously under one policy configuration. Detection rules cover NPI, policy identifiers, medical record numbers, SSNs, and financial account data. Enforcement actions (block, redact, flag) and access controls are configured by team and workflow. Every configuration change is version-logged with a tamper-evident before/after delta.

03

Every AI interaction inspected and logged

From the first call, every AI request and response passes through the detection pipeline. NPI, claims data, and policyholder identifiers are enforced per policy before any model processes the content. The tamper-proof audit log captures the complete record — available for state insurance examination requests, internal compliance reviews, and SOX IT audit submissions.

Compliance mapping

Six frameworks. One policy layer.

Each compliance obligation maps to a specific Arbitex capability. All bundles are active simultaneously — no separate configuration per framework or jurisdiction.

GLBA Safeguards Rule
16 CFR Part 314

NPI detection and access controls for annuity, life, and mortgage-related insurance products. Every NPI access logged with user context and policy version.

NAIC Model Law
Insurance Data Security

State-level insurance data security compliance mapped to one policy configuration. Covers policyholder data, claims records, and producer information.

CCPA
Cal. Civ. Code §1798

Consumer rights-aware data handling for California policyholders. PII detection in-path before AI model access. Configurable by geography and data category.

NY SHIELD Act
N.Y. Gen. Bus. Law §899-bb

Private information protection for New York policyholders. Detection covers SSNs, financial account numbers, and health information — enforced in-path.

SOX §404
IT Controls + Audit Trail

Access controls and version-logged configuration changes for AI supporting financial reporting in insurance holding company structures.

NAIC AI Guidance
Model Bulletin on AI Use

Audit documentation infrastructure for AI use in underwriting and claims — supports insurer filings and state regulatory inquiry responses.

Related Resources

Insurance Use Case

NAIC and GLBA compliance controls

DLP Protection

Inspect every AI prompt for sensitive data

Compliance Frameworks

Pre-built policy packs for regulatory requirements

Audit Log

Tamper-proof activity trail

AI adoption in insurance starts with data sovereignty.

Arbitex gives carriers, MGAs, and TPAs the governance layer to deploy AI in claims, underwriting, and customer service without creating policyholder data exposure. Every AI call inspected. Every AI call logged. Claims data never leaves your environment.