Data security
Your insurance data stays yours, even when AI is at work.
Baza protects operational, policyholder, and claims data through strict access boundaries, read-only connections, PII masking, and zero-data-retention AI processing where supported.
How data stays controlled
- Control Clear organisational and workspace boundaries
- Minimise Sensitive-data exposure kept purposefully narrow
- Monitor Security-relevant access events stay visible
- Improve Practices evolve as risks and regulation change
Practical safeguards
The controls behind the claim.
Specific protections for how insurance data is accessed, analysed, and handled across Baza.
- 01
Tenant and workspace isolation
Application and database safeguards keep each organisation and workspace scoped to its own data.
- 02
Role-based access, closed by default
Defined roles shape access. Missing or unclear permission is denied rather than assumed.
- 03
Zero data retention for AI
Supported AI processing defaults to settings that prevent providers from retaining or collecting your data.
- 04
PII masking before AI
Supported AI and schema-preview workflows mask sensitive details, including common African identifier formats.
- 05
Read-only connected data access
Database queries are constrained to read-only operations with validation, timeouts, and result limits.
- 06
Isolated code execution
Generated analysis code runs in an isolated, guarded environment, contained from the rest of your systems.
Control model
Four questions clarify who can reach what.
Baza scopes access through ownership, workspace, responsibility, and what the task needs.
- 1 Which organisation owns the data?
- 2 Which workspace is it scoped to?
- 3 What does this role allow?
- 4 What information does the task need?
Supporting controls
Encryption in transit and at rest
Stored files are encrypted at rest, and connected database traffic is protected with TLS.
Security monitoring
Relevant tenant, workspace, and access events are monitored.
Responsible AI
AI that works on your data, not from it.
Supported AI processing is configured to minimise what models receive and prevent providers from retaining or collecting your data.
- 01 / Retention
AI providers: zero data retention (ZDR) enforced
AI routing defaults to settings that prevent model providers from retaining or collecting your data.
- 02 / Minimisation
Sensitive details masked
Supported AI and schema-preview workflows mask PII, including common African identifiers and formats.
- 03 / Containment
Read-only and isolated
Connected database queries stay read-only, while generated analysis code runs in an isolated environment.
Built for recognised standards.
We build the controls and evidence required for independent review.
Baza does not currently claim SOC 2 attestation or ISO 27001 certification. GDPR-aligned describes our controls, not a certification.- SOC 2 Type II Type II ready
- ISO 27001 Certification ready
- GDPR Controls aligned
Security is a maintained practice
Bring us your security questions.
We review and improve our practices as technology, threats, and regional regulation change, and go deeper with your team when needed.