Data security

Your insurance data stays yours, even when AI is at work.

Baza protects operational, policyholder, and claims data through strict access boundaries, read-only connections, PII masking, and zero-data-retention AI processing where supported.

How data stays controlled

  1. Control Clear organisational and workspace boundaries
  2. Minimise Sensitive-data exposure kept purposefully narrow
  3. Monitor Security-relevant access events stay visible
  4. Improve Practices evolve as risks and regulation change

Practical safeguards

The controls behind the claim.

Specific protections for how insurance data is accessed, analysed, and handled across Baza.

  1. 01

    Tenant and workspace isolation

    Application and database safeguards keep each organisation and workspace scoped to its own data.

  2. 02

    Role-based access, closed by default

    Defined roles shape access. Missing or unclear permission is denied rather than assumed.

  3. 03

    Zero data retention for AI

    Supported AI processing defaults to settings that prevent providers from retaining or collecting your data.

  4. 04

    PII masking before AI

    Supported AI and schema-preview workflows mask sensitive details, including common African identifier formats.

  5. 05

    Read-only connected data access

    Database queries are constrained to read-only operations with validation, timeouts, and result limits.

  6. 06

    Isolated code execution

    Generated analysis code runs in an isolated, guarded environment, contained from the rest of your systems.

Control model

Four questions clarify who can reach what.

Baza scopes access through ownership, workspace, responsibility, and what the task needs.

  1. 1 Which organisation owns the data?
  2. 2 Which workspace is it scoped to?
  3. 3 What does this role allow?
  4. 4 What information does the task need?
Organisation
Workspace
Role
Purpose Only what the task needs

Supporting controls

Encryption in transit and at rest

Stored files are encrypted at rest, and connected database traffic is protected with TLS.

Security monitoring

Relevant tenant, workspace, and access events are monitored.

Responsible AI

AI that works on your data, not from it.

Supported AI processing is configured to minimise what models receive and prevent providers from retaining or collecting your data.

  1. 01 / Retention

    AI providers: zero data retention (ZDR) enforced

    AI routing defaults to settings that prevent model providers from retaining or collecting your data.

  2. 02 / Minimisation

    Sensitive details masked

    Supported AI and schema-preview workflows mask PII, including common African identifiers and formats.

  3. 03 / Containment

    Read-only and isolated

    Connected database queries stay read-only, while generated analysis code runs in an isolated environment.

Built for recognised standards.

We build the controls and evidence required for independent review.

Baza does not currently claim SOC 2 attestation or ISO 27001 certification. GDPR-aligned describes our controls, not a certification.
  • SOC 2 Type II Type II ready
  • ISO 27001 Certification ready
  • GDPR Controls aligned

Security is a maintained practice

Bring us your security questions.

We review and improve our practices as technology, threats, and regional regulation change, and go deeper with your team when needed.