Skip to content
Security & Governance

Governed AI agents for enterprise insurance operations.

Layerup is built for workflows where auditability, approval controls, data handling, and operational visibility matter. Designed with enterprise IT, compliance, and security teams in mind.

ComplianceSOC 2 Type II · PCI DSS · HIPAA
ApprovalHuman-in-the-loop
AuditabilityReasoning + actions
AccessRole-based
DeploymentCloud · VPC · On-prem · Sovereign
01Certifications

Exceeding industry security and compliance standards.

Layerup's security program is independently certified and audited by third-party auditors, holding us to the highest industry standards.

Compliant01

PCI DSS

Cardholder data handled to PCI DSS standards — controls validated through independent third-party assessment.

Certified02

SOC 2 Type II

Security, availability, and confidentiality controls independently audited by third-party auditors — over time, not at a point in time.

Compliant03

HIPAA

PHI handled under HIPAA administrative, physical, and technical safeguards, with documented controls per tenant and per workflow.

02Governance

Governance is a feature, not a footnote.

Layerup encodes governance, auditability, and human control into the agent runtime — not bolted on after a deployment.

01

Auditability

Every action an agent takes is recorded — input data, model evidence, decision outcome, and downstream system writes — with timestamps and identity.

02

Reasoning visibility

Inspect why an agent did what it did. Reasoning traces are first-class artifacts, available to QA, compliance, and senior reviewers.

03

Human approval gates

Configurable approval requirements per workflow, line of business, dollar threshold, or risk tier. Humans stay in control of the work that matters.

04

Exception handling

Edge cases, low-confidence outputs, and policy violations route to the right human queue with full context — no silent failures.

05

Role-based access

Permissions and visibility aligned to your operating model — adjusters, examiners, underwriters, leads, oversight, IT, and compliance.

06

Secure integrations

Integrations follow your enterprise patterns — SSO, scoped service accounts, network controls, and least-privilege access to source systems.

07

Data handling

PHI, PII, and policyholder data are handled with documented controls, retention configuration, and isolation per tenant and per workflow.

08

QA workflows

Sample, score, and review agent outputs against your guidelines and operating expectations. Feedback loops continuously raise the floor.

09

Compliance support

Layerup supports regulatory and contractual obligations across jurisdictions and lines of business — including documentation and reporting needs.

10

Staged action lifecycle

Every effect is typed and idempotent — proposed, staged, approved, then committed to systems of record.

11

Tamper-evident audit

Hash-chained, tamper-evident audit trail per tenant — every decision reconstructable with evidence, model lineage, and reviewer attribution.

03Deployment

Deploy it where you deem fit.

Layerup supports every deployment topology — managed cloud, private VPC, your cloud of record, on-premises, or a sovereign region — with the same governance, audit lineage, and controls everywhere.

01

Managed cloud

Layerup-managed deployment with per-tenant isolation and documented controls — the fastest path to production.

02

Private VPC

Deploy inside a private VPC with your network controls, secrets, and isolation requirements intact.

03

Your cloud of record

Operate in your cloud of record across multiple regions, business lines, and workflows.

04

On-premises

Run the platform and your own models entirely inside your data center boundary.

05

Sovereign region

Pin data, compute, and model calls to a sovereign region to meet residency and regulatory obligations.

04Integrations

Hundreds of integrations, wherever your systems live.

Every Layerup deployment ships with hundreds of pre-built integrations, plus custom integrations for the systems only you run — from cloud platforms and internal tools to on-premises cores — all under the same least-privilege access and audit lineage.

01

Pre-built integrations

Hundreds of ready-made connectors to the systems insurance operations run on — claims, policy admin, billing, document, and communication platforms.

02

Cloud platforms

SaaS applications and cloud data stores connect through scoped service accounts and provider-native auth — never blanket credentials.

03

Internal tools

Homegrown portals, internal APIs, and line-of-business applications integrate through the same typed, policy-checked action layer.

04

On-premises systems

Legacy cores, databases, and file systems inside your data center boundary — reachable without exposing them to the public internet.

05

Custom integrations

Systems no connector covers get a custom integration built to your interface contract and delivered with your deployment.

06

Uniform governance

Every integration — pre-built or custom — inherits the same least-privilege access, policy checks, and tamper-evident audit trail.

05Guardrails

Extensive guardrails on the agent runtime.

Agents cannot act outside policy. Every plan, tool call, and write-back passes through independent checks before anything reaches a system of record.

01

Planner / executor / verifier separation

The runtime separates planning, execution, and verification. No single model call plans an action, performs it, and grades its own work.

02

Typed, idempotent actions

Every effect on a system of record is a typed, idempotent action — safe to retry, never duplicated, reversible until committed.

03

Policy checks on every tool invocation

Each tool call clears enterprise policy — role, scope, and segregation of duties — before it executes. No exceptions, no side doors.

04

Approval gates by threshold and risk tier

Actions stage into human approval queues by dollar threshold, risk tier, workflow, and line of business — enforced at the runtime, not bolted on.

05

Confidence thresholds and exception routing

Low-confidence outputs, edge cases, and policy violations route to the right human queue with full context — no silent failures.

06

Kill switch on the agent runtime

Suspend an agent, a workflow, or the entire runtime instantly. Staged actions freeze and nothing further commits until a human re-enables it.

07

Continuous evaluation and drift monitoring

Outputs are sampled, scored, and monitored for drift and regression against your guidelines — feedback loops continuously raise the floor.

Get in touch

Ready for an enterprise security review?

We work with IT, compliance, and security teams from the first conversation. Engage early and we will provide the documentation your program requires.