Built for trust. Engineered for security. Regzact gives insurers, MGAs and brokers a secure home for their most critical compliance data.
Access to the application is controlled, authenticated and logged.
Users can protect their accounts with multi-factor authentication, so a stolen password alone is not enough to sign in.
Access to data inside Regzact is governed by role-based access controls. Each user sees and changes only what their role allows.
Regzact enforces a password complexity standard, and credentials are stored hashed — never in plain text.
User activity is recorded in audit logs, so a firm can show what was done, by whom and when — the record an auditor or regulator will ask for.
Pre-configure user permissions based on the teams they are in.
Send tracked email messages to staff, partners and customers.
Our architecture uses the security and availability controls of Microsoft Azure, with Cloudflare at the network edge.
Regzact services and customer data are hosted in Microsoft Azure data centres in the EU and UK. Physical security of those facilities is managed by Microsoft.
Cloudflare provides network-edge defences in front of Regzact, including a web application firewall and DDoS protection, before traffic reaches Azure.
Production systems are monitored for anomalous behaviour. When events cross set thresholds, alerts are raised and acted on.
All data sent to or from Regzact is encrypted in transit over TLS, with HSTS enabled. Data at rest is encrypted using AES-256.
Regzact is built with disaster recovery in mind. Data is backed up regularly, and infrastructure is spread across Azure availability zones so the service can continue if one fails.
We engage independent third-party security specialists to perform penetration tests on the Regzact application and infrastructure, and remediate what they find.
Security is part of how Regzact is built and released, not a check at the end.
Our engineers follow secure development practices based on OWASP guidance, to limit exposure to risks such as SQL injection, cross-site scripting and cross-site request forgery.
Testing and staging environments are kept separate from production. Customer data is not used in development or test environments.
Multiple overlapping layers of security. From the network edge to data storage, each is secured preventing any single failure from compromising the system.
Everyone who works on Regzact is screened, trained and bound by confidentiality.
Staff complete security awareness training during onboarding and on a regular basis after that.
New employees are background-checked in line with the laws that apply to our business.
All employee contracts include a confidentiality agreement covering customer and company information.
Regzact processes personal data in line with the UK GDPR and the EU GDPR. A data processing agreement is available to customers.
We handle personal data as a processor for our customers under the UK GDPR and the EU GDPR, with data hosted in the EU.
A data processing agreement is available to customers, setting out how Regzact processes personal data on their behalf.
If your security or procurement team needs more detail for vendor due diligence, contact us and we will work through it with you.
Join insurers, MGAs, and brokers across the UK and Ireland who have made compliance a strategic advantage. Book a personalised demo and see Regzact working with your own network.