How We Protect Your Data

Encryption, security measures, and compliance

Our Commitment to Security

At AskFLC, protecting your data is our top priority. We implement industry-leading security measures, encryption standards, and compliance protocols to ensure your conversations, personal information, and uploaded files remain secure and private.

Multi-Layer Security Architecture

End-to-End Encryption

All data transmitted between your device and our servers is encrypted using industry-standard TLS 1.3 encryption protocol.

What this means for you:

  • Your conversations are encrypted in transit
  • Nobody can intercept or read your messages
  • Bank-level security for all communications

Secure Data Storage

Your data is stored in encrypted form on secure cloud infrastructure with multiple redundancy layers to prevent loss.

Storage security features:

  • AES-256 encryption at rest
  • Regular automated backups
  • Geographically distributed data centers
  • 24/7 infrastructure monitoring

Authentication & Access Control

How We Verify Your Identity:

Secure Authentication

We use secure OAuth 2.0 protocols for login, supporting multiple authentication providers (Google, Apple, email) to ensure only you can access your account.

Password Protection

Passwords are hashed using bcrypt with salt, making them virtually impossible to decrypt even in the unlikely event of a data breach.

Session Management

Secure session tokens expire after periods of inactivity, and you can remotely log out from all devices at any time.

Two-Factor Authentication (Coming Soon)

We're adding optional 2FA for an extra layer of security, requiring both your password and a verification code to log in.

File Upload Security

Protecting Your Documents

When you upload files (Premium+ feature), we take special measures to protect your documents:

Virus Scanning: All uploaded files are automatically scanned for malware and viruses before processing

File Type Validation: We verify file types to prevent malicious uploads

Secure Processing: Files are processed in isolated environments to prevent cross-contamination

Automatic Deletion: Temporary processing files are automatically deleted after analysis

Access Restrictions: Only you can access your uploaded files - not even our staff can view them without explicit permission

Compliance & Certifications

GDPR Compliant

We comply with the European Union's General Data Protection Regulation, ensuring:

  • Right to access your data
  • Right to data portability
  • Right to be forgotten
  • Transparent data practices

CCPA Compliant

California Consumer Privacy Act compliance provides California residents with:

  • Know what data we collect
  • Delete personal information
  • Opt-out of data sales (we don't sell data)
  • Non-discrimination rights

SOC 2 Type II

Our infrastructure undergoes annual third-party audits for:

  • Security controls
  • Availability standards
  • Confidentiality measures
  • Privacy protections

HIPAA Considerations

While not a covered entity, we follow HIPAA-aligned practices:

  • Encrypted data transmission
  • Access controls and audit logs
  • Secure data storage
  • Staff security training

Internal Security Practices

Employee Access Controls

Our employees have limited access to user data based on their role. Access is logged and regularly audited. We never access your conversations without explicit consent for support purposes.

Security Training

All team members undergo comprehensive security training and sign confidentiality agreements. We maintain a culture of security awareness.

Regular Security Audits

We conduct quarterly internal security audits and annual third-party penetration testing to identify and address vulnerabilities.

Incident Response Plan

We maintain a comprehensive incident response plan and will notify affected users within 72 hours of discovering any security breach.

Third-Party Services

Vetted Security Partners

We carefully select third-party services that meet our high security standards:

Cloud Infrastructure

Hosted on enterprise-grade cloud platforms (AWS/GCP) with SOC 2 Type II certification and 99.99% uptime SLA

Payment Processing

PCI DSS Level 1 compliant payment processors. We never store your complete credit card numbers

Analytics

Privacy-focused analytics that don't track individual users or share data with advertisers

What We Don't Do

Our Privacy Commitments:

We never sell your data to third parties, advertisers, or data brokers

We don't use your conversations to train AI models without explicit opt-in consent

We don't share personal information with insurance companies or agents without your explicit consent

We don't track you across other websites or apps

We don't require unnecessary permissions on your device beyond what's needed for core functionality

Reporting Security Issues

Found a Vulnerability?

We take security reports seriously and appreciate responsible disclosure. If you discover a security vulnerability:

Contact our security team:

Email: security@askflc.com

Please provide detailed information about the vulnerability and steps to reproduce it. We'll respond within 48 hours and work with you to address the issue.

Your Role in Security

While we implement robust security measures, you also play a crucial role in protecting your account:

  • Use a strong, unique password for your AskFLC account
  • Never share your login credentials with others
  • Log out when using shared or public computers
  • Be cautious about what personal information you share in conversations
  • Report suspicious activity to our support team immediately

Learn more in our Account Security Best Practices guide.

Copyright © 2026 FLC Insurance Services Inc. - All Rights Reserved.

This website is operated by FLC Insurance Services Inc., a licensed health insurance agency, and is required to comply with all applicable federal laws, including the standards established under 45 CFR § 155.220(c) and (d) and standards established under 45 CFR § 155.260 to protect the privacy and security of personally identifiable information.

By creating an account, you consent and to being contacted by an FLC Insurance Services Inc., agent or an agent you have found on our site by phone, email, and text/SMS to the home, office or mobile number(s) you provided, even if your provided number is on a National, State, or Private, Do Not Call List. If you are visually impaired, please call us directly at (800) 459-5750 for further assistance.