Security Policy
Last updated: 4 July 2026
We use technical, organizational, and administrative safeguards intended to protect InsureCompare accounts, product data, user submissions, billing records, analytics data, and service operations. This page summarizes our public security practices and how to report security concerns.
Account Security
Users are responsible for using a secure email account, keeping login credentials confidential, signing out from shared devices, and notifying us promptly if they suspect unauthorized account access. We may apply email confirmation, rate limits, anti-abuse checks, and session controls to protect accounts.
Data Protection
We limit access to service data based on operational need and use platform controls to help protect data in transit and at rest where supported by our infrastructure providers. Access to production data should be limited to authorized personnel and service providers who need it for support, operations, security, billing, or legal reasons.
User Uploads and Sensitive Data
Product-request uploads are intended for public or shareable product materials such as brochures and product disclosure sheets. Do not upload client medical records, identity documents, claims documents, private policy schedules, or other sensitive personal data unless you have authority and a lawful basis to do so.
Security Monitoring and Incident Response
We may log authentication events, usage events, abuse signals, payment events, AI usage metadata, and operational errors to detect misuse, investigate incidents, maintain service reliability, and meet legal or regulatory obligations. If we identify a data incident that requires notification, we will assess and respond according to applicable law.
Responsible Vulnerability Reporting
If you believe you found a security issue, contact us at support@insurecompareapp.com with enough detail for us to reproduce and investigate the issue.
Please do not:
- Access, modify, delete, copy, or disclose data that is not yours.
- Run destructive, disruptive, or high-volume testing.
- Attempt social engineering, phishing, spam, or physical attacks.
- Publicly disclose a vulnerability before we have investigated it.
We do not currently operate a paid bug bounty program. Reports are handled on a best-effort basis.