Policyholder Data Stays on Your
Organization's Machines.
Claims adjusters, underwriters, and service agents are using ChatGPT, Claude, and Copilot every day — pasting medical records, SSNs, financial histories, and claims data into prompts. Shield sits on your organization's machines and stops policyholder data from ever reaching an external AI model. No cloud. No vendor access. Just a local proxy that redacts sensitive data before it leaves your network.
Shield for Insurance is a local desktop application that stops policyholder data — medical records, SSNs, financial details, claims information, and payment data — from ever leaving your organization's computers before that data reaches ChatGPT, Claude, Copilot, or any AI model. It runs on your existing machines, requires no cloud infrastructure, and helps insurers meet HIPAA, GLBA, NAIC AI Principles, and state data security requirements without changing how claims adjusters, underwriters, and service agents use AI tools.
The NAIC's survey of 193 private passenger auto insurers found that 88% report using, planning to use, or planning to explore AI and machine learning models in their operations. For home insurers (194 surveyed), the figure was 70%, and for health insurers (93 surveyed), 92% reported AI/ML use. Insurance companies are among the most AI-forward industries — yet only 7% have successfully scaled AI systems beyond pilots, according to BCG's 2024 global study.
Insurance carriers operate under a complex regulatory web: HIPAA (health data), GLBA (financial privacy), state insurance data security laws (based on the NAIC model), GDPR (EU policyholders), CCPA (California residents), PCI DSS (payment data), and SOC 2 (vendor assurance). The NAIC Model Bulletin on AI (adopted December 2023) adds specific AI governance requirements. A single prompt sent to an external AI model can expose data subject to several of these frameworks simultaneously.
Shield runs locally on your insurance organization's machines — no cloud processing, no vendor data access. Policyholder PII, medical records, financial details, and proprietary actuarial data never reach external AI providers. The redaction mapping stays on your machine, inside your organization's network boundary.
Insurance teams handle the broadest range of sensitive data in any industry — and they're using AI
When a claims adjuster pastes a claimant's medical records into an AI prompt, or an underwriter shares an applicant's full financial and health history, that data leaves your organization's controlled environment. A single AI prompt can contain data subject to HIPAA, GLBA, state insurance regulations, GDPR, and PCI DSS — simultaneously. Shield eliminates this vector: sensitive policyholder information never leaves your network, so it never creates a compliance exposure across any of these frameworks.
Interactive Demo
What Insurance Data Looks Like in AI Prompts
Three real-world scenarios where insurance professionals send sensitive data to AI models. Click each tab to see the raw prompt with identifiable information — and how Shield redacts it before it leaves your network.
Compliance
How Shield Maps to Insurance Regulatory Frameworks
Insurance carriers operate under an overlapping set of federal, state, and international data protection regulations. Shield's local proxy architecture provides a single technical control that supports compliance across HIPAA, GLBA, NAIC AI Principles, GDPR, CCPA, PCI DSS, and SOC 2 — without adding cloud dependencies to your data governance scope.
| Framework | Scope | Key Requirement | How Shield Helps |
|---|---|---|---|
| HIPAA | Health insurers, P&C claims with medical records, life underwriting | Protect PHI — medical records, diagnoses, provider details. Breach notification requirements for unauthorized disclosures. Penalties up to $1.5M/year per violation category. | Redacts PHI — diagnoses, NPI numbers, procedure codes, medication lists — before prompts reach external AI. PHI never leaves the covered entity's control. Audit logs document every redaction for compliance evidence. |
| GLBA | All insurance companies handling nonpublic personal information (NPI) | Financial institutions must protect customer NPI — names, SSNs, account numbers, medical information. The Safeguards Rule requires technical controls. Penalties up to $100,000 per violation. | Redacts NPI before it reaches external AI systems. Reduces data exposure surface for GLBA-regulated information. Provides technical safeguard documentation for compliance assessments. |
| NAIC AI Principles | All insurers using AI — underwriting, pricing, claims, marketing | Model Bulletin (Dec 2023) establishes expectations: fairness, accountability, transparency, safety. AI Systems Evaluation Tool (piloting 2026) will assess governance and risk mitigation. | Supports consumer protection principle by preventing unauthorized data disclosure through AI channels. Tamper-evident audit logs provide documentation for AI Systems Evaluation Tool assessments. |
| GDPR | EU/EEA policyholder data processed by any insurer globally | Data minimization, purpose limitation, security of processing. Cross-border transfer restrictions. Fines up to €20M or 4% of global annual turnover. | Implements data minimization by default — policyholder PII is redacted before it reaches non-EU AI providers. Supports GDPR's 'data protection by design and by default' requirement. |
| CCPA / CPRA | California resident policyholders and claimants | Right to know, delete, opt-out of sale/sharing. Sensitive personal information (SSN, precise geolocation, health data) requires enhanced protection. | Prevents sensitive PI (SSNs, health data, geolocation) from being shared with AI providers — which could constitute a 'sale' or 'sharing' under CCPA. Reduces exposure for CCPA compliance. |
| PCI DSS | Payment card data in premium payments and claims settlements | Protect cardholder data — PAN, expiry, CVV. Never store sensitive authentication data. Maintain secure systems and access controls. | Detects and redacts payment card numbers (PAN), expiry dates, and bank account details before they reach external AI systems. Prevents accidental cardholder data exposure in AI prompts. |
| SOC 2 | Insurers providing services to enterprise clients — vendor assurance | Trust Services Criteria: Security, Availability, Confidentiality. Independent auditor assessment of controls protecting customer data. | Redaction audit trails provide evidence of confidentiality controls. Demonstrates technical measures to protect client data from unauthorized AI exposure — supporting SOC 2 attestation. |
Architecture
Policyholder Data Never Leaves Your Insurance Network
Shield runs as a local proxy on your organization's machines. When a claims adjuster, underwriter, or service agent sends a prompt to an AI model, Shield intercepts it — redacts all policyholder PII, PHI, financial data, and protected records — and only then forwards the clean prompt to the external LLM. The redaction mapping stays on your machine, inside your organization's network boundary.
Local Installation
Install Shield on any Mac, Windows, or Linux machine. No cloud infrastructure, no vendor data access, no policyholder data leaves your network.
One Environment Variable
Set SHIELD_PROXY_URL and every AI call from that machine flows through Shield automatically. Zero code changes to your existing tools — Guidewire, Duck Creek, or any core system.
Full Audit Trail
Every redaction event is logged with a cryptographic hash. Prove to regulators, auditors, and state insurance departments exactly what data was caught and when — with tamper-evident integrity.
Configurable Policies
Choose which data categories to redact — PII, PHI, PCI, financial. Add custom patterns for your claim numbering schemes and producer codes. Run in audit-only mode to validate coverage first.
FAQ
Common Questions
Related Articles
Ready to Protect Your Policyholders' Data?
Shield installs in minutes. Your policyholders' medical records, SSNs, financial details, and claims data stay on your organization's machines — where HIPAA, GLBA, and state insurance regulators expect them to be.
Last updated: July 22, 2026