Industry Insurance & insurtech

Security Across Every System a Policy Touches

A quote engine written last year, a policy administration system written decades ago, and a broker portal in between — one audit scope, all holding health and financial data. One self-hosted platform covers them, and none of it leaves your infrastructure.

Legacy and modern in one view

The policy administration system and the quote API produce findings in the same model, ranked against each other rather than in separate tools.

Claimant data never leaves

Health questionnaires, claims history and payment details sit under special-category rules. The scanner that reads that code runs on your infrastructure.

Broker and partner APIs in scope

Distribution runs through other people's software. Your integration surface is discovered and tracked, not assumed.

Governance evidence by default

ICT governance expectations want a documented, repeatable process. The platform records one as the result of running it.

Key challenges

What Insurance Engineering Teams Run Into

Few insurers get to start from scratch. They run thirty years of systems that are all still in use, and a regulator treats them as one.

Codebases nobody wants to touch

A policy engine with two decades of accumulated rules is not getting rewritten to satisfy a scanner. It still has to be covered.

Distribution you do not control

Brokers, aggregators and MGAs integrate on their timetable. Every new partner adds surface that your own release process never saw.

Special-category data in ordinary systems

Health and biometric answers end up in the same forms, logs and test fixtures as everything else — which raises the cost of a leak in code that looks routine.

Group reporting on different clocks

Several legal entities, several supervisors, and one engineering organisation trying to produce evidence for all of them from one set of tools.

Clause map

What Supervisors Expect

Insurance-specific obligations that reach application security, and the general ones that reach it hardest.

DORA European Union

scope · ICT risk identification

Insurers and reinsurers are financial entities in scope. Continuous identification and monitoring of ICT vulnerabilities supporting critical or important functions, with documented remediation.

How Whitespots helps

Continuous scanning across all systems with a dated record per finding, scoped so each legal entity in a group can report on its own systems.

DORA RTS on ICT risk management European Union

vulnerability management · change management

Documented vulnerability management procedures that record every detected vulnerability and monitor its resolution, and change management that verifies ICT security requirements for every software change.

How Whitespots helps

The policy is easier to write when the process behind it already emits evidence: ranked findings, owners, quality gates and closure dates.

Solvency II European Union

operational risk management

Operational risk — including risk arising from systems failure — identified, measured, monitored and reported as part of the governance system.

How Whitespots helps

Application risk expressed in terms a risk function can consume: severity, exposure, age, and which business function the affected system supports.

GDPR European Union

special categories · security of processing

Health data is special category, and technical measures must be regularly tested, assessed and evaluated for effectiveness.

How Whitespots helps

Regular testing that is continuous rather than annual, on infrastructure where the code and the findings stay inside your perimeter.

NIS2 European Union

risk-management measures

Where an entity falls in scope, measures must include vulnerability handling and disclosure, security in acquisition and development, and supply-chain security.

How Whitespots helps

Every change scanned, with automatic validation, notifications and per-severity SLAs, plus dependency and container coverage for the supply chain.

NAIC model law · state DFS rules United States

information security programme

Licensees maintain a written information security programme with risk assessment, and several states require regular penetration testing and vulnerability assessments.

How Whitespots helps

Define how often each system is scanned and how findings are validated. The platform runs that process and keeps its results — formal evidence that the programme is actually followed.

References reflect published text as of August 2026 and describe obligations rather than a certification we grant. Scope varies by entity, jurisdiction and size — confirm with your compliance function. US state requirements differ materially; treat the row above as a pointer, not a summary of any one state.

Platform

What Whitespots Gives an Insurance Security Team

Coverage that does not assume a modern codebase, and reporting that assumes several supervisors.

Self-hosted 01

Policyholder data, and the map to reach it, stay inside the perimeter

  • No sub-processors to explain Nothing to name in a customer or supervisor review.

  • Zero outbound data No code, findings, logs or usage data leave your servers.

  • Leave whenever you want Exit is a database export, not a vendor negotiation.

See deployment options →
Legacy coverage 02

Systems older than your tooling land in the same queue

  • Nothing skipped for lack of a tool Custom and in-house scanners for languages nothing else covers.

  • Pentests and scanners in one record Manual findings imported alongside any scanner's output.

  • One flaw is one finding Deduplicated across every scanner.

Explore the platform →
Partner and API surface 03

Distribution integrations stop being a blind spot

  • See every exposed integration External asset and subdomain discovery.

  • The right team gets the finding Routed to whoever owns the integration.

  • New exposure caught as it appears Continuous rescan when the surface changes.

How it works →
Group reporting 04

Separate evidence for each supervisor from one platform

  • One instance, many legal entities Scoping per legal entity and per product.

  • Deadlines you can prove you met SLAs per severity for verification, assignment and resolution.

  • Audit-ready at any moment Exportable reports for internal audit and supervisors.

See the platform tiers →
Outcomes

Where It Lands

What an insurance security function is usually asked to produce.

  • Scenario

    A supervisor asks how ICT vulnerabilities are monitored

    With Whitespots platform

    A continuous record per system rather than an annual assessment date.

  • Scenario

    A legacy policy system falls in scope

    With Whitespots platform

    Covered through whichever scanner reaches it, in the same queue as everything else.

  • Scenario

    A broker integration goes live

    With Whitespots platform

    The new surface is discovered and tracked, with findings routed to its owner.

  • Scenario

    Group audit needs evidence per legal entity

    With Whitespots platform

    Separate exports per legal entity from one platform instance.

FAQ

What Insurance Teams Ask First

Most of our systems are not modern. Will a scanner even reach them?

The platform is not a single scanner — it is the findings database and the workflow around whichever scanners reach your code. Where only an in-house or niche tool covers a language or platform, that tool is integrated into continuous scanning like any other: it runs automatically and its results go through the same deduplication and validation. You do not have to scale or automate it yourself.

Does this apply if we are below the DORA or NIS2 thresholds?

Scope is a question for your compliance function, and it varies by entity type and size. The operational case is independent of it: continuous vulnerability management with an audit trail is what makes any of these reviews short, whichever one you fall under.

How do we keep health data out of the security tooling?

By not sending anything outward. The platform runs on your infrastructure and processes your code and scanner output in place, so special-category data never becomes a transfer question in the first place.

Can we accept some types of risk as a policy decision?

Yes. Agree with stakeholders which issues are acceptable, then add validation rules that accept them automatically. Anything else can be accepted during triage, permanently or for a set number of days; when a temporary acceptance expires, the finding returns to the queue.

We run several legal entities with one engineering team. Does that fit?

Yes, that is common in insurance. One platform instance serves the whole engineering team, while scopes, roles and reports are set per legal entity, so each one gets its own evidence.

Cover Every System, Not Just the Modern Half

Start with a free external scan of your public surface, or talk to us about a self-hosted deployment scoped to your legal entities and their supervisors.