Security
Security at PolicyLink
Last modified: August 19, 2026
Security vendors and customers should treat the PolicyLink host as a legitimate insurance intake service. The controls below are implemented in the PolicyLink platform today. They are not a promise of perfect security, and they do not replace an agency's own obligations when handling personal information.
Transport encryption
Public PolicyLink traffic is served over HTTPS so data is encrypted in transit between the browser and our servers.
Public host isolation
The PolicyLink public host does not serve the RiskAdvisor agent login or admin panel. Those internal tools stay on the application domain. This host is for customer-facing PolicyLinks and these transparency pages.
Carrier login with MeasureOne
Some PolicyLinks ask the customer to connect a carrier account. That step is optional and only appears when the agency enables it.
Carrier login credentials are entered in MeasureOne, a third-party connector, not on a PolicyLink form. PolicyLink does not collect or store those carrier passwords. MeasureOne's own security practices apply to that login widget.
These transparency pages never ask for carrier credentials. If a page claiming to be PolicyLink asks you to type a carrier password into an ordinary form, treat it as suspicious and use Report Abuse.
Monitoring
We monitor PolicyLink application errors and operational events, including Sentry alerting for notable failures.
Responsible disclosure
If you believe you have found a security issue in PolicyLink, email us. Include enough detail for us to reproduce the issue. Do not access data that is not yours, and do not disrupt service while testing.
We will acknowledge reports sent to the address below and work to understand and fix confirmed issues.