Security and governance
Six companies, one group, and a set of controls that has to work across the boundaries between them. Stated without a badge we have not earned, and explicit about what is still preparation.
Controls at a glance
Eight things that hold across the group rather than in one company or in a premium tier.
Encryption in transit and at rest
Traffic between a client and a platform, and between one operating company and the next, runs over TLS. Stored records, call media, transcripts, and backups are encrypted at rest. Neither is an upsell and there is no configuration where either is off.
Least privilege across companies
One identity, a separate grant of access per company. Signing in once is a convenience; being authorized everywhere is not. Roles are scoped to an agency, a hierarchy branch, a campaign, or a program rather than to a whole company.
Separation of health information
The companies that collect and use health detail are kept apart from the ones that do not, and the ones that do not are not given access they have no reason to hold. It is an architectural boundary, not a policy sentence.
Credential and key management
Credentials are issued per company, per environment, and per purpose, held in a managed secret store rather than in configuration files, rotated on a schedule, and revocable individually so a rotation is a deploy rather than an outage.
Vendor and subprocessor review
Anything that touches regulated data is reviewed before it is adopted and re-reviewed on a schedule. The inventory names what each vendor processes, why, and where. Commodity inputs are bought deliberately, not accumulated.
Incident response and notification
A documented runbook that is exercised rather than filed, with a named owner per company. If an incident affects your data you get a direct notification naming what was affected and what we did, not a line on a status page.
Retention aligned to obligations
Windows are set per record class against carrier and state requirements rather than against convenience, in both directions. Too short and a dispute cannot be answered; too long and the group holds regulated content it has no reason to keep.
Business continuity
Backups that are restored as an exercise rather than assumed, documented recovery objectives per platform, and the ability to operate one company while another is degraded, because they do not share a single point of failure.
Which company holds which data
The separation claim is only worth making if it is specific. Here is the split, company by company, including the ones that deliberately hold nothing sensitive.
| Company | Holds | Boundary |
|---|---|---|
| Solved Marketing | Acquisition records, consent records, contact channels | No health detail. It is not collected here and not shared into here. |
| Solved Telephony | Call media, transcripts, messages, call detail records | Carries regulated content rather than interpreting it. Retention set per account. |
| AgentTech Dialer | Contacts, calls, recordings, transcripts, compliance scores | Conversation content, which can contain health detail a caller volunteers. Treated as sensitive. |
| Solved Enroll | Client records, health profiles, quotes, recommendations, applications | Where health information concentrates by design. Access logged as a sensitive read. |
| Solved Solutions | Producer licensing, appointment state, hierarchy, commissions | Producer and contract data. No client health detail. |
| Solved Insurance and Solved Re | Product, underwriting, and risk records | In development pending state approval. Nothing is in force and no policyholder data exists yet. |
Health information concentrates in Solved Enroll on purpose. The flows that cross into the acquisition and distribution companies carry references and outcomes rather than medical answers; see which company holds what.
Access control and least privilege
One identity, separate grants. The whole design is the refusal to conflate signing in with being authorized.
- A grant per company. Entitlement in one platform says nothing about entitlement in the next, and each grant is issued, reviewed, and revoked on its own.
- Roles, not people. Access is granted by role so a change of job is one edit rather than a scavenger hunt through six systems.
- Scoped narrowly. To an agency, a hierarchy branch, a campaign, or a program. A downline branch is visible to its own upline and to nobody sideways of it.
- No privileged internal path. Every platform is multi-tenant because every platform has external customers, so an internal team is a tenant on the same rules.
- Sensitive reads are logged. Recording playback, health profile access, and consent record access are logged with the identity, the record, and the grant that permitted it.
- Engineering access is reviewed. Production data is reached through a reviewed path rather than through a standing grant, and administrative roles are held by few people.
How a grant is bounded
- Company
- Issued by one operating company and valid nowhere else in the group.
- Scope
- An agency, a branch, a campaign, or a program, rather than a whole tenant.
- Purpose
- Read-only or a named subset of resources, so a reporting integration cannot write.
- Lifetime
- Per environment, rotated on a schedule, revocable on its own.
Keys, vendors, and the things that go wrong quietly
Three programs that produce no visible output until the day they are the only thing that matters.
Credential and key management
Secrets live in a managed store rather than in configuration files or a shared document. They are issued per company, per environment, and per purpose, rotated on a schedule, and revocable individually. Nothing that reaches regulated data is embedded in a client application, because a credential shipped to a browser or a handset is a credential you have published.
Vendor and subprocessor review
Anything that processes regulated data is reviewed before adoption and re-reviewed on a schedule, and the inventory records what it processes, why, and where. The group buys commodity inputs deliberately, cloud, payments, and data, and builds the layers that carry margin, which keeps the vendor list short enough to actually review.
Retention
Windows are set per record class against carrier and state requirements. Records with different obligations age on different schedules, so deleting a call recording does not delete the activity record that references it. The fastest way to reduce exposure on stored regulated content is to hold less of it for less time, and retention is set with that in mind.
Incident response and continuity
Two commitments. You hear about an incident from us, and an incident in one company does not become an incident in all six.
- A runbook that is exercised. Documented response steps with a named owner per company, rehearsed rather than filed, including who declares an incident and who talks to customers.
- Direct notification. If an incident affects your data you get a notification naming what was affected and what we did. A service incident goes to the operating company status page; a security incident does not stop there.
- Cross-company incidents have one owner. When something spans two companies, the group takes the coordination rather than leaving two teams to discover each other.
- Evidence, not narrative. After the fact you can have the records for the affected window rather than a summary of them.
- Restores are tested. Backups are exercised as restores, with recovery objectives documented per platform rather than assumed.
- No single point of failure across companies. The platforms do not share one dependency whose loss would take the whole group down together.
Where the program actually stands
We would rather be believed about a smaller claim than doubted about a larger one, so this section says exactly what is true, what is in progress, and what we will not say.
What is true today
The controls on this page are running: encryption in transit and at rest, one identity with separate grants per company, an architectural separation of the companies that handle health information, secrets in a managed store, vendor review before adoption, retention windows aligned to carrier and state requirements, logged sensitive reads, and a response runbook with a named owner per company.
What is underway
Formal audit readiness work across the group: control documentation, evidence collection, periodic access reviews, subprocessor re-review on a schedule, policy management, tabletop exercises against the runbook, and restore testing with documented recovery objectives. This is preparation, and calling it anything else would be the first thing to distrust on this page.
What we will not claim
There is no completed SOC 2 report, no HIPAA audit or attestation, no named auditor, no certificate number, and no badge anywhere on this site. We do not publish or imply an executed business associate agreement with any named party. When an audit completes, this section will say so plainly and the report will be available under NDA.
What you can get today: a completed security questionnaire, a written description of the control set for the companies in your scope, the encryption and retention specifics that apply to your account, and a conversation with the people who operate it. Ask at contact@solvedventures.io.
Security contact
One address for the whole group, routed to the team that owns the system you found the issue in.
- Email. contact@solvedventures.io, with a subject line starting "Security".
- Phone. +1 (866) 415-6192 for anything urgent enough that waiting for an email reply is the wrong call.
- Any property in the group. Reports about any of the six operating companies or their sites can start here; we will route it rather than send you elsewhere.
- Procurement questions welcome. Send the questionnaire to the same address and name the companies in scope.
Responsible disclosure
If you believe you have found a vulnerability in any Solved platform, API, or website, email contact@solvedventures.io with a subject line starting "Security" and enough detail to reproduce the issue. We acknowledge reports within one business day, route them to the team that owns the system, keep you updated while we work, and credit you when a fix ships if you want the credit.
In return we ask that you give us a reasonable window to fix the issue before disclosing it publicly, that you do not access, modify, exfiltrate, or retain data belonging to anyone else, and that you do not degrade service for customers while testing. Please do not run load tests, place fraudulent calls, send unsolicited messages through the network, or submit applications through the enrollment platform as part of a test, because several of those have consequences for real people rather than for us. We will not pursue legal action against researchers acting in good faith within those terms.
If a report turns out to describe a control we have chosen rather than a defect, we will tell you that plainly and explain the reasoning instead of closing the thread.
FAQs
Security questions
Are you SOC 2 certified?
No, and we will not imply otherwise. There is no completed SOC 2 report, no named auditor, and no certificate behind this page. Formal audit readiness work is underway across the group: control documentation, evidence collection, periodic access reviews, vendor and subprocessor review, and an incident response runbook that is exercised. That is preparation, not a result. When an audit completes we will say so plainly here.
Are you HIPAA compliant?
We have not completed a HIPAA audit or attestation and do not claim one. What we can describe is the control set: encryption in transit and at rest, least privilege with grants scoped per company, an architectural separation between the companies that handle health information and those that do not, logged access to health profiles and recordings, and retention windows aligned to carrier and state requirements. Where a business associate agreement is required for a specific relationship, it is negotiated with that counterparty, and we do not publish or imply an executed agreement with anyone.
Why does a holding company have a security page at all?
Because the interesting risks in a vertically integrated group are the ones between the companies rather than inside any one of them. Each operating company can describe its own controls, and they do. What only the group can describe is how access is separated across them, which company holds which class of data, and what happens when an incident spans two.
Does one login get someone into every company?
No, and that distinction is the core of the model. A person has one identity and a separate grant of access in each company they are entitled to use. A contracted producer might hold a dialer seat and a quoting login and nothing at all in telephony administration. Each grant is issued, reviewed, and revoked on its own.
How is health information kept away from the companies that do not need it?
Structurally. Health profiles live in Solved Enroll, and the flows that cross into the acquisition and distribution companies carry references and outcomes rather than medical answers. The warehouse minimizes health detail on the way in, because the group operating numbers do not need it. Access to a health profile is logged as a sensitive read rather than as an ordinary query.
What happens if a credential is compromised?
The blast radius is what the scoping decided in advance. Credentials are issued per company, per environment, and per purpose, so one stolen token does not reach a second company. Each one is revocable on its own. On the telephony side, destination allowlists, velocity limits, and spend caps bound the cost of a compromised calling credential specifically.
Will you complete a security questionnaire?
Yes, including the parts where the honest answer is not yet. Send it to contact@solvedventures.io and tell us which operating companies are in scope, because the answers differ between a telephony account and an enrollment cohort.
How do I report a vulnerability?
Email contact@solvedventures.io with a subject line starting "Security" and enough detail to reproduce the issue. Reports about any property in the group can start there and will be routed to the team that owns the system. The disclosure terms are on this page.
Something else? Contact us
Need this in writing?
Send your questionnaire and name the companies in scope. We will complete it, including the parts where the honest answer is not yet.