Trust Center
Built for the trust your license depends on.
Insurance advisors are trusted with sensitive personal and financial information. Here is exactly how Egean handles it — in plain language, with no vague marketing claims.
Security pillars
Residency
All Egean infrastructure storing client data is located in Canada. Data collected through advisor websites, Ege Quoter, and EGEPilot is not replicated outside Canada.
Encryption
Data is encrypted at rest using industry-standard encryption on the underlying storage, and in transit using TLS for every connection.
PIPEDA
Consent tracking, access requests, and retention controls are built into the platform, aligned with PIPEDA and provincial regulators' expectations.
Access Controls
Multi-factor authentication, role-based permissions, and a logged audit trail of who accessed or changed a client record.
PIPEDA alignment, in practice
What "PIPEDA by design" actually means here
- Consent tracking — where a client provides consent to be contacted or to have their information used for a quote, that consent is recorded against their file.
- Right to access — advisors can retrieve what information is held on a given client so a data-access request can be answered.
- Retention & disposal controls — data-retention settings exist at the platform level so client information is not held indefinitely by default.
- Breach-response posture — Egean maintains an internal process for identifying, containing, and notifying affected parties and regulators, consistent with PIPEDA's breach-reporting obligations.
This describes our committed practice and platform design. It is not a substitute for your agency's own PIPEDA compliance obligations as the entity collecting client information — talk to your compliance advisor about how Egean fits into your existing obligations.
In plain language
What this means for you and your clients
- Your clients' data is stored on servers in Canada. It does not leave the country.
- Data is encrypted both while it's stored and while it's moving between systems.
- We follow PIPEDA — consent, access requests, and data retention are built into the platform, not handled ad hoc.
- Access to client data is controlled: MFA, role-based permissions, and a logged audit trail of who touched what.
- We do not claim certifications we don't hold. Where one is in progress, it's marked as such — never implied.
Certifications
Third-party attestations in progress — published here when complete.
Have a security question before you commit?
30 minutes · your data · no pressure
Talk to Us About Security