Solved Enroll entered private beta, and AI Voice Agents went live on Solved Telephony. Read the updates
Trust

Security and governance

Six companies, one group, and a set of controls that has to work across the boundaries between them. Stated without a badge we have not earned, and explicit about what is still preparation.

Controls at a glance

Eight things that hold across the group rather than in one company or in a premium tier.

Encryption in transit and at rest

Traffic between a client and a platform, and between one operating company and the next, runs over TLS. Stored records, call media, transcripts, and backups are encrypted at rest. Neither is an upsell and there is no configuration where either is off.

Least privilege across companies

One identity, a separate grant of access per company. Signing in once is a convenience; being authorized everywhere is not. Roles are scoped to an agency, a hierarchy branch, a campaign, or a program rather than to a whole company.

Separation of health information

The companies that collect and use health detail are kept apart from the ones that do not, and the ones that do not are not given access they have no reason to hold. It is an architectural boundary, not a policy sentence.

Credential and key management

Credentials are issued per company, per environment, and per purpose, held in a managed secret store rather than in configuration files, rotated on a schedule, and revocable individually so a rotation is a deploy rather than an outage.

Vendor and subprocessor review

Anything that touches regulated data is reviewed before it is adopted and re-reviewed on a schedule. The inventory names what each vendor processes, why, and where. Commodity inputs are bought deliberately, not accumulated.

Incident response and notification

A documented runbook that is exercised rather than filed, with a named owner per company. If an incident affects your data you get a direct notification naming what was affected and what we did, not a line on a status page.

Retention aligned to obligations

Windows are set per record class against carrier and state requirements rather than against convenience, in both directions. Too short and a dispute cannot be answered; too long and the group holds regulated content it has no reason to keep.

Business continuity

Backups that are restored as an exercise rather than assumed, documented recovery objectives per platform, and the ability to operate one company while another is degraded, because they do not share a single point of failure.

Which company holds which data

The separation claim is only worth making if it is specific. Here is the split, company by company, including the ones that deliberately hold nothing sensitive.

CompanyHoldsBoundary
Solved Marketing Acquisition records, consent records, contact channels No health detail. It is not collected here and not shared into here.
Solved Telephony Call media, transcripts, messages, call detail records Carries regulated content rather than interpreting it. Retention set per account.
AgentTech Dialer Contacts, calls, recordings, transcripts, compliance scores Conversation content, which can contain health detail a caller volunteers. Treated as sensitive.
Solved Enroll Client records, health profiles, quotes, recommendations, applications Where health information concentrates by design. Access logged as a sensitive read.
Solved Solutions Producer licensing, appointment state, hierarchy, commissions Producer and contract data. No client health detail.
Solved Insurance and Solved Re Product, underwriting, and risk records In development pending state approval. Nothing is in force and no policyholder data exists yet.

Health information concentrates in Solved Enroll on purpose. The flows that cross into the acquisition and distribution companies carry references and outcomes rather than medical answers; see which company holds what.

Access control and least privilege

One identity, separate grants. The whole design is the refusal to conflate signing in with being authorized.

  • A grant per company. Entitlement in one platform says nothing about entitlement in the next, and each grant is issued, reviewed, and revoked on its own.
  • Roles, not people. Access is granted by role so a change of job is one edit rather than a scavenger hunt through six systems.
  • Scoped narrowly. To an agency, a hierarchy branch, a campaign, or a program. A downline branch is visible to its own upline and to nobody sideways of it.
  • No privileged internal path. Every platform is multi-tenant because every platform has external customers, so an internal team is a tenant on the same rules.
  • Sensitive reads are logged. Recording playback, health profile access, and consent record access are logged with the identity, the record, and the grant that permitted it.
  • Engineering access is reviewed. Production data is reached through a reviewed path rather than through a standing grant, and administrative roles are held by few people.

The identity model in detail

How a grant is bounded

Company
Issued by one operating company and valid nowhere else in the group.
Scope
An agency, a branch, a campaign, or a program, rather than a whole tenant.
Purpose
Read-only or a named subset of resources, so a reporting integration cannot write.
Lifetime
Per environment, rotated on a schedule, revocable on its own.

Keys, vendors, and the things that go wrong quietly

Three programs that produce no visible output until the day they are the only thing that matters.

Credential and key management

Secrets live in a managed store rather than in configuration files or a shared document. They are issued per company, per environment, and per purpose, rotated on a schedule, and revocable individually. Nothing that reaches regulated data is embedded in a client application, because a credential shipped to a browser or a handset is a credential you have published.

Vendor and subprocessor review

Anything that processes regulated data is reviewed before adoption and re-reviewed on a schedule, and the inventory records what it processes, why, and where. The group buys commodity inputs deliberately, cloud, payments, and data, and builds the layers that carry margin, which keeps the vendor list short enough to actually review.

Retention

Windows are set per record class against carrier and state requirements. Records with different obligations age on different schedules, so deleting a call recording does not delete the activity record that references it. The fastest way to reduce exposure on stored regulated content is to hold less of it for less time, and retention is set with that in mind.

Precision instruments measuring a component

Incident response and continuity

Two commitments. You hear about an incident from us, and an incident in one company does not become an incident in all six.

  • A runbook that is exercised. Documented response steps with a named owner per company, rehearsed rather than filed, including who declares an incident and who talks to customers.
  • Direct notification. If an incident affects your data you get a notification naming what was affected and what we did. A service incident goes to the operating company status page; a security incident does not stop there.
  • Cross-company incidents have one owner. When something spans two companies, the group takes the coordination rather than leaving two teams to discover each other.
  • Evidence, not narrative. After the fact you can have the records for the affected window rather than a summary of them.
  • Restores are tested. Backups are exercised as restores, with recovery objectives documented per platform rather than assumed.
  • No single point of failure across companies. The platforms do not share one dependency whose loss would take the whole group down together.

Where each company publishes status

Where the program actually stands

We would rather be believed about a smaller claim than doubted about a larger one, so this section says exactly what is true, what is in progress, and what we will not say.

What you can get today: a completed security questionnaire, a written description of the control set for the companies in your scope, the encryption and retention specifics that apply to your account, and a conversation with the people who operate it. Ask at contact@solvedventures.io.

Security contact

One address for the whole group, routed to the team that owns the system you found the issue in.

  • Email. contact@solvedventures.io, with a subject line starting "Security".
  • Phone. +1 (866) 415-6192 for anything urgent enough that waiting for an email reply is the wrong call.
  • Any property in the group. Reports about any of the six operating companies or their sites can start here; we will route it rather than send you elsewhere.
  • Procurement questions welcome. Send the questionnaire to the same address and name the companies in scope.

Responsible disclosure

If you believe you have found a vulnerability in any Solved platform, API, or website, email contact@solvedventures.io with a subject line starting "Security" and enough detail to reproduce the issue. We acknowledge reports within one business day, route them to the team that owns the system, keep you updated while we work, and credit you when a fix ships if you want the credit.

In return we ask that you give us a reasonable window to fix the issue before disclosing it publicly, that you do not access, modify, exfiltrate, or retain data belonging to anyone else, and that you do not degrade service for customers while testing. Please do not run load tests, place fraudulent calls, send unsolicited messages through the network, or submit applications through the enrollment platform as part of a test, because several of those have consequences for real people rather than for us. We will not pursue legal action against researchers acting in good faith within those terms.

If a report turns out to describe a control we have chosen rather than a defect, we will tell you that plainly and explain the reasoning instead of closing the thread.

FAQs

Security questions

Are you SOC 2 certified?

No, and we will not imply otherwise. There is no completed SOC 2 report, no named auditor, and no certificate behind this page. Formal audit readiness work is underway across the group: control documentation, evidence collection, periodic access reviews, vendor and subprocessor review, and an incident response runbook that is exercised. That is preparation, not a result. When an audit completes we will say so plainly here.

Are you HIPAA compliant?

We have not completed a HIPAA audit or attestation and do not claim one. What we can describe is the control set: encryption in transit and at rest, least privilege with grants scoped per company, an architectural separation between the companies that handle health information and those that do not, logged access to health profiles and recordings, and retention windows aligned to carrier and state requirements. Where a business associate agreement is required for a specific relationship, it is negotiated with that counterparty, and we do not publish or imply an executed agreement with anyone.

Why does a holding company have a security page at all?

Because the interesting risks in a vertically integrated group are the ones between the companies rather than inside any one of them. Each operating company can describe its own controls, and they do. What only the group can describe is how access is separated across them, which company holds which class of data, and what happens when an incident spans two.

Does one login get someone into every company?

No, and that distinction is the core of the model. A person has one identity and a separate grant of access in each company they are entitled to use. A contracted producer might hold a dialer seat and a quoting login and nothing at all in telephony administration. Each grant is issued, reviewed, and revoked on its own.

How is health information kept away from the companies that do not need it?

Structurally. Health profiles live in Solved Enroll, and the flows that cross into the acquisition and distribution companies carry references and outcomes rather than medical answers. The warehouse minimizes health detail on the way in, because the group operating numbers do not need it. Access to a health profile is logged as a sensitive read rather than as an ordinary query.

What happens if a credential is compromised?

The blast radius is what the scoping decided in advance. Credentials are issued per company, per environment, and per purpose, so one stolen token does not reach a second company. Each one is revocable on its own. On the telephony side, destination allowlists, velocity limits, and spend caps bound the cost of a compromised calling credential specifically.

Will you complete a security questionnaire?

Yes, including the parts where the honest answer is not yet. Send it to contact@solvedventures.io and tell us which operating companies are in scope, because the answers differ between a telephony account and an enrollment cohort.

How do I report a vulnerability?

Email contact@solvedventures.io with a subject line starting "Security" and enough detail to reproduce the issue. Reports about any property in the group can start there and will be routed to the team that owns the system. The disclosure terms are on this page.

Something else? Contact us

Need this in writing?

Send your questionnaire and name the companies in scope. We will complete it, including the parts where the honest answer is not yet.