Every policy covered. Every session too.
IRDAI-aligned access governance over policy data, TPAs, and agent networks. Every request is verified.
- IRDAI guidelines_
- DPDP Act_
- ISO 27001_
- TPA access governed_
- Least privilege_
Insurance runs on an extended enterprise: tied agents and brokers on their own devices, surveyors in the field, TPAs processing claims, bancassurance partners inside bank branches. All of them touch policyholder and health data that DPDP and IRDAI guidance treat as high-sensitivity.
The core systems are often long-lived, with policy administration platforms that predate modern identity, and the access reality is the widest BYOD estate in financial services.
The five or six places this actually changes something.
- Agent & broker portalsClientless access with MFA, watermarking and download policy. Personal devices stay contained, and policyholder data is never persisted locally.Clientless Access
- TPA & partner accessScoped tiles, time-boxed engagements and session recording: outsourcing oversight with replay attached.Third-Party Access
- Surveyor field workGeo- and time-contextual mobile access to claims systems, matching how field assessment actually happens.
- Legacy policy adminMFA and device gates placed in front of platforms that cannot be modified.Legacy Applications
- Health-data handlingLeast-privilege scoping with full audit: the access-minimisation posture DPDP expects of the most sensitive category of data.
The numbers this vertical gets asked for.
- External user modelClientless: nothing to install on an agent or broker device
- In-session controlWatermarking, clipboard and download policy on by default
- Partner sessionsScoped, time-boxed and recorded per engagement
- Legacy platformsMFA and device gates in front of applications that cannot be changed
- ContextIdentity, device, location and time evaluated on every request
Govern the session,not the device.
What the extended enterprise looks like once containment moves.
Attribution returns
The distribution network gains a named human and a contained session behind every login.
Questions answer
IRDAI and DPDP access questions are answered from logs rather than reconstructed from memory.
Legacy gains gates
Policy administration platforms get modern access control without a modernisation project.
The check moved to the login, before the applications.
A private life insurer put a second factor in front of the Windows sign-in as well as the applications behind it, and admitted only registered machines whose operating-system state the policy accepts. Identity stays in the directory already in use, and the deployment spans the insurer's own data centre and its recovery site.
- MFA at the desktop_
- Registered devices_
- Application by application_

Thousands of external users,
one governed access model.
- Identity signals
- Device signals
- Network signals
- Application signals
You can verify identity, device, network, and app on every request. One decision engine evaluates all four before a single packet reaches anything — not four separate tools.
Nothing to install on an agent's device. Clientless sessions carry MFA, watermarking and download policy, so the widest BYOD estate in financial services needs no fleet management behind it.
One console, not five. ZTNA, ZTAA, IAM, MFA, and SSO — retire the point products.
We are enterprise-grade compliant. Architecture aligned to NIST SP 800-207 and CSA SDP; supports the controls required by PCI DSS, HIPAA, GDPR, SOX, and ISO 27001.
Policyholder data never persists on the endpoint. The session is contained rather than the device managed, which is the only model that works for agents, brokers and surveyors you will never own.
- NIST SP 800-207
- ISO 27001
- CSA SDP
"decision": "allow"Insurance, answered.
Tap a question. If yours is not here, a specialist for this sector can answer it.
Talk to a specialistSee it running against your own apps.
A 30-minute walkthrough, tailored to your stack and deployment: cloud, on-premise or hybrid.
Book a demo




