Information Security Standards, SOC2 Alignment & Data Protection Commitments
Version 1.0 | Effective: April 2025TruCover Wellness handles some of the most sensitive categories of personal data: health records, insurance information, and financial data. We treat data security not as a compliance checkbox but as a foundational trust requirement. Our security programme is aligned with the SOC2 Trust Service Criteria — Security, Availability, Processing Integrity, Confidentiality, and Privacy.
Health data is the most sensitive category of data on our platform. We implement specific controls:
| Data Type | Employee | HR Admin | Agent / Intermediary |
|---|---|---|---|
| Individual health records | Own records only | No access | No access |
| Consultation notes | Own records only | No access | No access |
| Mental wellness responses | Own records only | No access | No access |
| Aggregate wellness reports | No access | Department/company level | No access |
| Insurance policy details | Own policy | Company policy | Client portfolio |
| Claims details | Own claims only | Aggregate only | Client claims (aggregate) |
| Commission data | No access | No access | Own commission |
In the event of a data security incident, TruCover will:
Corporate clients may request the following from TruCover: