TruCover Wellness ← All Policies

Data Security Policy

Information Security Standards, SOC2 Alignment & Data Protection Commitments

Version 1.0 | Effective: April 2025
Document TitleData Security Policy
Security StandardSOC2 Type II Aligned (Trust Service Criteria)
Governing LawIT Act, 2000 | DPDP Act, 2023 | IRDAI Data Guidelines
Applicable ToAll users — employees, HR, agents, intermediaries
Last UpdatedApril 2025

1Security Philosophy

TruCover Wellness handles some of the most sensitive categories of personal data: health records, insurance information, and financial data. We treat data security not as a compliance checkbox but as a foundational trust requirement. Our security programme is aligned with the SOC2 Trust Service Criteria — Security, Availability, Processing Integrity, Confidentiality, and Privacy.

2Key Security Controls

2.1 Encryption

2.2 Access Control

2.3 Network Security

2.4 Infrastructure & Hosting

3Health Data Handling

Health data is the most sensitive category of data on our platform. We implement specific controls:

4Data Access by Role

Data TypeEmployeeHR AdminAgent / Intermediary
Individual health recordsOwn records onlyNo accessNo access
Consultation notesOwn records onlyNo accessNo access
Mental wellness responsesOwn records onlyNo accessNo access
Aggregate wellness reportsNo accessDepartment/company levelNo access
Insurance policy detailsOwn policyCompany policyClient portfolio
Claims detailsOwn claims onlyAggregate onlyClient claims (aggregate)
Commission dataNo accessNo accessOwn commission

5Incident Response

In the event of a data security incident, TruCover will:

6Vendor & Third-Party Security

7Employee & Internal Team Security

8Requesting Security Information

Corporate clients may request the following from TruCover:

9Contact

Security Queries
bd@trucover365.com
Data Breach Reporting
+91 95023 47365 | bd@trucover365.com
DPA Requests
bd@trucover365.com
Data Security Officer
R Sathish
Security Direct Line
+91 778771768