A separate agency stack
Each agency is provisioned in its own application and database stack. Customer, policy, employee, and reporting rows are not pooled with another agency's records in shared customer tables.
Security and data boundaries
Before onboarding, an agency should be able to understand where its records live, how access is scoped, what activity is auditable, and which controls are still in pilot development. Keelridge documents those boundaries instead of substituting a badge for the conversation.
Current product posture
These statements describe the current deployment model. They are not a certification or a promise that one control satisfies every agency's requirements.
Each agency is provisioned in its own application and database stack. Customer, policy, employee, and reporting rows are not pooled with another agency's records in shared customer tables.
Access begins with an approved identity and a defined agency role. Owners, managers, account managers, and operating staff receive different permissions and data scopes.
Agency source files and identity-bearing records belong in controlled databases or private storage—not in the application source repository. Application credentials remain server-side.
Defined classes of sensitive access and consequential changes write application audit events, including identity and role changes, exports, source intake, and configuration changes.
Public demo boundary
The public demo is deliberately separate from every client agency. It does not ask visitors to upload files or enter agency information.
Explore the fictional demoCurrent limits
Security questions
No. The current deployment model provisions a separate application and database stack for each agency. Agency customer, policy, employee, and reporting rows are not pooled into shared multi-tenant tables.
No. The public demo is a separate fictional agency built from synthetic customers, employees, policies, opportunities, documents, and financial figures. Business-changing actions are disabled.
Keelridge does not currently claim SOC 2 certification or completed enterprise compliance coverage. Security readiness, data handling, agreement terms, and the agency's requirements are reviewed before a paid pilot is accepted.
No. An initial fit conversation needs the operating question and a description of the available report types—not customer records, policy documents, credentials, or other confidential agency data.
Before sharing records
A private walkthrough and high-level source review establish whether a deeper security and implementation conversation is warranted. Do not send customer data with an initial inquiry.