INSTANDA · Trust Center

Instanda Trust Center

Trust center

INSTANDA maintains a public trust center documenting ISO 27001:2022, SOC 2, Cyber Essentials, and PCI DSS SAQ A compliance.

InsuranceUnited KingdomInsurtechPolicy AdministrationUnderwritingClaimsProperty and CasualtyLife InsuranceHealth InsuranceDigital DistributionNo CodeCore SystemsMGABrokerWebhooksMicrosoft AzureEmbedded Insurance
Trust center: https://app.trustero.com/trust/instanda

Certifications & Compliance

ISO 27001:2022SOC 2Cyber EssentialsPCI DSS SAQ A

Source

Trust Center

instanda-trust-center.yml Raw ↑
generated: '2026-07-25'
method: searched
probe: true
url: https://app.trustero.com/trust/instanda
hosted_by: Trustero (third-party trust-centre platform)
first_party_security_page: https://instanda.com/platform-security
http_status: 200
machine_readable: false
note: >-
  The Trustero trust centre is linked from the instanda.com footer and returns
  HTTP 200, but it is a client-rendered React application - the served HTML is an
  empty shell with the title "Trustero" and no certification text, so its contents
  cannot be harvested without executing JavaScript. The certifications recorded
  below are therefore taken from INSTANDA's own first-party security page at
  instanda.com/platform-security, not scraped from Trustero.
certifications:
- ISO 27001:2022
- SOC 2
- Cyber Essentials
- PCI DSS SAQ A
controls_published:
  encryption_at_rest: AES-256 (Azure full disk encryption)
  encryption_in_transit: AES-256 SSL certificates
  siem: true
  dlp: true
  waf: machine-learning web application firewall
  firewall: next-generation firewall with SSL VPN, deep-packet inspection, intrusion detection/prevention
  ssdlc: >-
    "Our Secure Software Development Lifecycle (SSDLC) includes secure code
    reviews, vulnerability assessments, full penetration testing, and threat
    modeling."
  hosting: Microsoft Azure
  data_residency: client data stored in required geographies to meet regional regulations
gaps:
  security_contact_published: false
  vulnerability_disclosure_policy: false
  security_txt: false
  subprocessor_list_public: false
  audit_reports_downloadable: false
  note: >-
    No security@ address, no responsible-disclosure or bug-bounty page, and no
    RFC 9116 security.txt was found on any INSTANDA host. Named certifications
    are claimed but no report or certificate is publicly downloadable.
evidence:
- source: https://instanda.com/platform-security
  status: 200
  kind: first-party-security-page
  keywords: [iso 27001:2022, soc 2, cyber essentials, pci dss saq a, ssdlc, penetration testing, siem, dlp, waf]
- source: https://app.trustero.com/trust/instanda
  status: 200
  kind: hosted-trust-center
  keywords: []
  note: JavaScript-rendered shell; no keywords extractable from served HTML.