Security Across Every System a Policy Touches
A quote engine written last year, a policy administration system written decades ago, and a broker portal in between — one audit scope, all holding health and financial data. One self-hosted platform covers them, and none of it leaves your infrastructure.
Legacy and modern in one view
The policy administration system and the quote API produce findings in the same model, ranked against each other rather than in separate tools.
Claimant data never leaves
Health questionnaires, claims history and payment details sit under special-category rules. The scanner that reads that code runs on your infrastructure.
Broker and partner APIs in scope
Distribution runs through other people's software. Your integration surface is discovered and tracked, not assumed.
Governance evidence by default
ICT governance expectations want a documented, repeatable process. The platform records one as the result of running it.
What Insurance Engineering Teams Run Into
Few insurers get to start from scratch. They run thirty years of systems that are all still in use, and a regulator treats them as one.
Codebases nobody wants to touch
A policy engine with two decades of accumulated rules is not getting rewritten to satisfy a scanner. It still has to be covered.
Distribution you do not control
Brokers, aggregators and MGAs integrate on their timetable. Every new partner adds surface that your own release process never saw.
Special-category data in ordinary systems
Health and biometric answers end up in the same forms, logs and test fixtures as everything else — which raises the cost of a leak in code that looks routine.
Group reporting on different clocks
Several legal entities, several supervisors, and one engineering organisation trying to produce evidence for all of them from one set of tools.
What Supervisors Expect
Insurance-specific obligations that reach application security, and the general ones that reach it hardest.
scope · ICT risk identification
Insurers and reinsurers are financial entities in scope. Continuous identification and monitoring of ICT vulnerabilities supporting critical or important functions, with documented remediation.
How Whitespots helps
Continuous scanning across all systems with a dated record per finding, scoped so each legal entity in a group can report on its own systems.
vulnerability management · change management
Documented vulnerability management procedures that record every detected vulnerability and monitor its resolution, and change management that verifies ICT security requirements for every software change.
How Whitespots helps
The policy is easier to write when the process behind it already emits evidence: ranked findings, owners, quality gates and closure dates.
operational risk management
Operational risk — including risk arising from systems failure — identified, measured, monitored and reported as part of the governance system.
How Whitespots helps
Application risk expressed in terms a risk function can consume: severity, exposure, age, and which business function the affected system supports.
special categories · security of processing
Health data is special category, and technical measures must be regularly tested, assessed and evaluated for effectiveness.
How Whitespots helps
Regular testing that is continuous rather than annual, on infrastructure where the code and the findings stay inside your perimeter.
risk-management measures
Where an entity falls in scope, measures must include vulnerability handling and disclosure, security in acquisition and development, and supply-chain security.
How Whitespots helps
Every change scanned, with automatic validation, notifications and per-severity SLAs, plus dependency and container coverage for the supply chain.
information security programme
Licensees maintain a written information security programme with risk assessment, and several states require regular penetration testing and vulnerability assessments.
How Whitespots helps
Define how often each system is scanned and how findings are validated. The platform runs that process and keeps its results — formal evidence that the programme is actually followed.
References reflect published text as of August 2026 and describe obligations rather than a certification we grant. Scope varies by entity, jurisdiction and size — confirm with your compliance function. US state requirements differ materially; treat the row above as a pointer, not a summary of any one state.
What Whitespots Gives an Insurance Security Team
Coverage that does not assume a modern codebase, and reporting that assumes several supervisors.
Policyholder data, and the map to reach it, stay inside the perimeter
-
No sub-processors to explain Nothing to name in a customer or supervisor review.
-
Zero outbound data No code, findings, logs or usage data leave your servers.
-
Leave whenever you want Exit is a database export, not a vendor negotiation.
Systems older than your tooling land in the same queue
-
Nothing skipped for lack of a tool Custom and in-house scanners for languages nothing else covers.
-
Pentests and scanners in one record Manual findings imported alongside any scanner's output.
-
One flaw is one finding Deduplicated across every scanner.
Distribution integrations stop being a blind spot
-
See every exposed integration External asset and subdomain discovery.
-
The right team gets the finding Routed to whoever owns the integration.
-
New exposure caught as it appears Continuous rescan when the surface changes.
Separate evidence for each supervisor from one platform
-
One instance, many legal entities Scoping per legal entity and per product.
-
Deadlines you can prove you met SLAs per severity for verification, assignment and resolution.
-
Audit-ready at any moment Exportable reports for internal audit and supervisors.
Where It Lands
What an insurance security function is usually asked to produce.
- Scenario
A supervisor asks how ICT vulnerabilities are monitored
With Whitespots platformA continuous record per system rather than an annual assessment date.
- Scenario
A legacy policy system falls in scope
With Whitespots platformCovered through whichever scanner reaches it, in the same queue as everything else.
- Scenario
A broker integration goes live
With Whitespots platformThe new surface is discovered and tracked, with findings routed to its owner.
- Scenario
Group audit needs evidence per legal entity
With Whitespots platformSeparate exports per legal entity from one platform instance.
What Insurance Teams Ask First
Most of our systems are not modern. Will a scanner even reach them?
The platform is not a single scanner — it is the findings database and the workflow around whichever scanners reach your code. Where only an in-house or niche tool covers a language or platform, that tool is integrated into continuous scanning like any other: it runs automatically and its results go through the same deduplication and validation. You do not have to scale or automate it yourself.
Does this apply if we are below the DORA or NIS2 thresholds?
Scope is a question for your compliance function, and it varies by entity type and size. The operational case is independent of it: continuous vulnerability management with an audit trail is what makes any of these reviews short, whichever one you fall under.
How do we keep health data out of the security tooling?
By not sending anything outward. The platform runs on your infrastructure and processes your code and scanner output in place, so special-category data never becomes a transfer question in the first place.
Can we accept some types of risk as a policy decision?
Yes. Agree with stakeholders which issues are acceptable, then add validation rules that accept them automatically. Anything else can be accepted during triage, permanently or for a set number of days; when a temporary acceptance expires, the finding returns to the queue.
We run several legal entities with one engineering team. Does that fit?
Yes, that is common in insurance. One platform instance serves the whole engineering team, while scopes, roles and reports are set per legal entity, so each one gets its own evidence.
Cover Every System, Not Just the Modern Half
Start with a free external scan of your public surface, or talk to us about a self-hosted deployment scoped to your legal entities and their supervisors.