Which identities touched policyholder data last night?
The data behind your float is the target: policyholder PII, claims, and PHI, held across every carrier you own. Attackers rarely break in. They log in, with valid credentials, from a broker portal, a claims vendor, a service account.
You reconcile premiums, reserves, and claims to the cent.
Access is never reconciled.
Entitlement is asserted in your role model; behavior is the only proof. CINQUE reads all five control points together and shows where the two disagree, across every operating company.
| Persona | Entitled, per RBAC | Observed, per CINQUE | Variance |
|---|---|---|---|
| Broker / agent portal | Quote and bind, own book | Reached other agents' books | BOUNDARY CROSSED |
| Claims service account | Read claims, batch window | New scopes, off-window | SCOPE DRIFT |
| Third-party TPA identity | Read assigned claims | Read and bulk-export PII | NEW EXPORT PATH |
| Underwriting AI agent | Recommend pricing | Recommend and approve | FOUR-EYES BREAK |
| Reinsurance data feed | Ceded-loss exchange, continuous | Ceded-loss exchange, continuous | RECONCILED |
Detection tells you what happened. Context tells you whether it was supposed to happen.
Four places carriers point it first.
Brokers, agents, and TPAs
What contracted identities actually touched across the book, on portals and well beyond them.
Claims and the data layer
Where PII, PHI, and claims data move, and which identity moved it, on the systems that hold your float.
Non-human identities
Service accounts, Shadow AI, and the agents entering underwriting and claims workflows, each baselined as a persona of its own.
Mergers and post-close
Standing privilege, orphaned admins, and duplicate identity stores inherited at close, across acquired carriers.
NYDFS and NAIC ask for a living inventory and an annual attestation.
Sign it knowing how access is actually used.
NYDFS 23 NYCRR Part 500 and the NAIC Insurance Data Security Model Law require a written security program, access controls, MFA, an asset inventory, and third-party oversight, assessed and certified annually.
CINQUE for Insurance security leaders
Which identities touched policyholder data last night? The ledger a carrier never balances: access, across brokers, TPAs, claims vendors, and every operating company you own.
- Brokers, agents, and TPAs: what contracted identities actually touched across the book
- Claims and the data layer: where PII, PHI, and claims data move, and which identity moved it
- Underwriting and claims agents baselined as personas of their own
- Mergers and post-close: standing privilege, orphaned admins, duplicate identity stores
Your data, handled like we mean it. You choose the export: limited, point-in-time, analyzed in an isolated environment, and deleted after your readout. Ask us for the data-handling summary; we are a security company and we expect the question.