FeaturesPricingAboutContact

Security & trust

What we actually do to protect your data. No badges we haven't earned, no "bank-grade" or "military-grade" claims — just what's true, and how you can check it yourself.

Encrypted at rest and in transit — and backups are actually tested by restoring them, not just taken.

Every brokerage's data is isolated and checked on the server, on every request — never just hidden in the interface.

A human approves everything Redline sends, and you can export your whole book, any time — no lock-in.

A tamper-evident log of every security-relevant event, and an honest roadmap toward independent certification.

Your database and documents are encrypted on disk

A stolen laptop, a copied disk, or a leaked backup file are unreadable without the key. Every brokerage's documents are encrypted with their own separate key, derived from the master key, so a problem scoped to one brokerage can never expose another's files — and a second, narrower layer of encryption protects the most sensitive personal details even inside a database that's currently open. Signed-in owners can see this brokerage's own real, live status on Settings → Security.

Always sent over an encrypted connection

When deployed, Redline is only ever served over HTTPS — our own deployment guide requires a reverse proxy that terminates real TLS, refuses plain HTTP, and sends a real HSTS header telling the browser to never try plain HTTP again.

Backed up automatically, and proven to actually work

A backup of your database and files runs automatically every night, encrypted the same way the live database always is. An untested backup isn't a backup, so a real, periodic drill actually restores one into a throwaway location and confirms it holds the exact same data, byte for byte, that was backed up — not just claimed.

Real security headers, everywhere

Every response carries a real set of browser-security headers — the ones that stop a page being framed by another site, stop a browser from guessing a file's type into something dangerous, and lock down what a page is even allowed to do. Our Content Security Policy is fully ENFORCING, not just report-only — a page-injected script is actually blocked from running, not just logged after the fact.

Uploads are checked, not just trusted

A document you upload is checked by what its bytes actually are, not just the filename's own claim — a disguised file, or a file type that could carry active content (like a raw SVG image), is rejected before it's ever stored.

No card data ever touches us

When payments arrive, they'll be handled directly by a payment processor (Stripe) built for exactly that — your card details are never something Redline's own servers see or store.

Only your brokerage can see your clients

Every query in Redline is scoped to your own brokerage — checked on the server, on every single request, not just hidden in the interface. This isn't just a design intention: a real, automated check creates two brand-new brokerages before every single release and proves neither can reach the other's data, by id or by list.

A human approves everything Redline sends

A chase email, a letter, a query to an insurer — nothing drafted here ever sends without a real person clicking Approve first. Always. This is a genuine product rule enforced on the server, not just a UI convention.

Real two-step verification

Every team member can turn on two-step verification (a real authenticator app, not SMS) for their own account, and an owner can require it for the whole team — with genuine server-side enforcement, not just a suggestion.

We can't casually browse your data

There's no admin panel or account role — not even ours — that browses across brokerages. On the rare occasion our own team needs a direct look at one brokerage's data to help with a support request, we can only ask: an owner has to approve that request inside the product, choosing how long it lasts, before any access exists at all — time-boxed, hash-chain-logged, and visible to every owner the moment it's requested and the moment it's approved, never silent.

See and control your own sessions

Every signed-in device or browser is listed for you, with a genuine one-click "sign out everywhere else." Changing your password or turning two-step verification on or off signs out every OTHER session automatically — never left quietly logged in somewhere you forgot about.

What we can — and can't — see

There is no admin panel or hidden account, ours included, that browses across brokerages — every request our own team's tools make goes through the exact same per-brokerage check a real one would. Day to day, nobody at Redline looks at your data. When helping with a specific support request occasionally needs a direct look, our team can only ask: an owner has to approve that request themselves, from inside the product, choosing exactly how long it lasts — no approval, no access. Every owner is notified the moment a request comes in and the moment one is approved, the request and its outcome are recorded in the same tamper-evident log mentioned elsewhere on this page, and access can be ended instantly, at any time, from Settings → Security. Whoever operates the underlying server infrastructure could still technically reach the raw files — no software control changes that, and we won't pretend otherwise — but approval-gating means that access is never silent: it's requested, decided by you, and time-boxed, not automatic or open-ended. Even a direct look at the raw file on disk is unreadable without the key. We don't yet hold an independent certification confirming any of this from the outside — see the honest roadmap below.

You may notice one thing we deliberately did NOT build: encryption where even we hold no key at all — sometimes called "zero-knowledge" or client-side encryption. We considered it and turned it down, on purpose, and we'd rather tell you why than let you assume we simply didn't think of it. Its failure mode is permanent, irreversible loss of your client book the day someone forgets a passphrase — and brokers, like everyone, forget passwords regularly. As an insurance professional, you carry real record-keeping obligations; "the file is permanently unrecoverable" is not an answer you could give a client, an insurer, or a regulator, and it's not one we're willing to ship as a feature. Every real access-control question this could have answered is instead answered by what's actually built above: nobody looks without your explicit, in-app approval, every access is visible and logged, and you can leave with everything, any day, with nothing held hostage to a forgotten secret. Recoverable by design, always.

Can someone take my book with them?

No — not a departing employee, and not anyone else. Every safeguard below is enforced on the server, not just hidden in the interface. Here's exactly how, point by point.

  • Every single query the product makes is scoped to your own brokerage, checked on the server — an account executive can never pull up another brokerage's clients, and nobody at your OWN brokerage can see another's if you don't grant it.
  • Your files are encrypted with a key unique to your brokerage — not one shared key covering everyone on Redline.
  • Roles are enforced on the server, not just hidden in the interface: what an account executive can see, approve, or export is a real, checked permission, not a suggestion a determined person could click past.
  • A whole-book export is logged — who did it, when, and every other owner at your brokerage is notified the moment it happens.
  • Every signed-in session is visible to the person who owns it, with a genuine one-click way to sign every other one out.
  • Two-step verification is available for everyone, and an owner can require it for the whole team.

Your data, on your terms

Every client, policy, renewal, task, claim, communication, and stored document — as a single download, any time you want it, from inside the product. Want to leave altogether? Ask, and your account is deleted — see our Pricing page's FAQ for exactly what that means. No lock-in, no waiting on a support ticket.

A tamper-evident activity log

Every security-relevant event — sign-ins, password changes, two-step verification, data exports — is recorded in a log that's cryptographically chained together: each entry is mathematically linked to the one before it, so a row that's quietly altered or deleted afterward breaks the chain in a way an owner can actually check, right from Settings → Security.

You can never be locked out of your own book

Forget your password? A real, self-service emailed link gets you back in — no support ticket, no waiting on us. If your brokerage has more than one Owner, any of them can trigger the same real reset for a locked-out colleague without ever seeing or setting that person's password. Lost your two-step device? A one-time recovery code (given to you, once, the moment you turn two-step on) gets you straight in. Every one of these paths is exercised by a real, automated test on every single change we ship — not just tested once and hoped to keep working.

If something ever goes wrong

If a real security incident ever affects your data, we'll tell you as soon as we genuinely know something — not held back until everything is perfectly resolved. That means what happened, roughly when, what we've already done about it, and what happens next, with a further update by a time we actually commit to, not silence. UK/EU customers: this matches the honest 72-hour expectation UK GDPR sets for notifying the ICO once we're aware a breach affects personal data — the same clock we'd be holding ourselves to internally, not a promise invented just for this page. This commitment is backed by a real, detailed internal runbook (containment, working out what happened, rotating what's affected, restoring from backup) that our own team actually follows — not just this public summary of it.

The larger, longer-established platforms hold SOC 2 Type II — a real, earned standard we don't hold yet, so we won't claim it. Here's the honest, specific roadmap instead of a badge we haven't earned.

Cyber Essentials (UK)

Targeted next

A government-backed, self-assessed baseline — the first, cheapest, fastest-to-earn independent standard on this roadmap. Not yet held.

Cyber Essentials Plus (UK)

Planned after that

The same standard, independently verified rather than self-assessed. Not yet held.

ISO 27001 / SOC 2 Type II

Planned for US expansion

The standard the larger, longer-established platforms already hold. A real, multi-month undertaking we're planning for, not claiming early.

Independent penetration test

Planned

A paid, external test of the live product by people whose job is finding what we missed — scheduled as a real, human task, not a code change.

The questions a cautious broker — or their IT-savvy nephew — would actually ask, answered before you have to ask them.

Where is my data stored?

In a single database on the server Redline runs on — not spread across a dozen third-party services. Every brokerage's rows live in the same database file, kept apart from every OTHER brokerage's by a check the server runs on every single request (never just hidden in the interface) — see "Can someone take my book with them?" above for exactly how that isolation works.

Who can access it?

Only signed-in members of your own team, and only what their role permits — an account executive doesn't see what an owner sees. Redline's own team can only ever REQUEST a look at your data for a genuine support request — never take one; an owner has to approve it, in-app, choosing how long it lasts, before any access exists — see "What we can — and can't — see" above.

Is it encrypted — where, and how?

At rest: AES-256-GCM for the whole database and every stored document, with each brokerage's documents under their own separate key, plus a second, narrower layer over the most sensitive personal details. In transit: HTTPS only, with a real HSTS header. See Settings → Security for this brokerage's own real, live status.

Can you technically read my files?

Whoever operates the underlying server could technically reach the raw data — that's true of any hosted software, and we won't pretend otherwise. What actually stops it happening: no admin panel or hidden account exists that browses across brokerages, our own team can only REQUEST a look at your data (never take one), an owner has to approve that request in-app before any access exists, and every request and approval is logged and visible to every owner. We deliberately did not build "zero-knowledge" encryption where even we hold no key — see "What we can — and can't — see" above for exactly why: its failure mode is permanently losing your client book to a forgotten passphrase, which is a worse outcome than the risk it would remove.

What happens if you get breached — will you tell me, and how fast?

Yes, as soon as we genuinely know something — not held back until everything is perfectly resolved. See the incident-response commitment just below for specifics, including the honest 72-hour regulatory expectation that applies to UK/EU customers.

What if you go out of business?

We don't carry a formal data-escrow or business-continuity guarantee today — we're a small, independently-run product, and it would be dishonest to imply otherwise. What genuinely protects you instead: "Export everything" already works, today, any day you want it, with no advance notice needed from us — you are never dependent on us deciding to give you your data back.

Can I get my data out?

Yes — every client, policy, renewal, task, claim, communication, and stored document, as a single download, any time, from inside the product. No support ticket, no waiting.

Do you sell or share anything?

No. We don't sell client data, and we don't share it with third parties for marketing or any other purpose. This marketing site itself carries no tracking scripts and no third-party analytics, on the same principle.

Do you train AI on my data?

No — Redline ships with its AI provider slot set to "none," and every AI-adjacent feature already works fully without one (server-filled templates, computed answers, real keyword/full-text search). If a provider is ever turned on, it answers or drafts using YOUR OWN data for YOUR OWN request, in the moment — never to train a shared model on it.

Found a problem?

If you believe you've found a genuine security issue, please email [email protected] directly rather than posting it publicly — a real person reads every message, and we'll get back to you. See our Vulnerability Disclosure Policy for exactly what to expect from us in return.

Questions about any of this? Get in touch.

Get started free