Security and data protection
Built for trust and compliance.
Forsio handles sensitive insurance information. Insurance records are stored in Stockholm, collection from insurers is based on the customer’s BankID-signed consent, and the customer controls sharing. Here we describe the safeguards and their scope.
Data protection
How the data is protected.
Collection from insurers is based on the customer’s BankID-signed consent. Insurance records are stored inside the EU. Customers can withdraw consent and request erasure as described in the product privacy policy.
- 01
BankID verified
- 02
Consent signed
- 03
EU storage (Stockholm)
- 04
Withdrawal ready
Principles
How we handle data.
Insurance records in the EU
Insurance records are stored with Amazon Web Services in Stockholm. Other processing and subprocessors are described in the product privacy policy.
BankID-signed consent
Anchored in the customer's own signature. Traceable and revocable.
Encryption in transit and at rest
Data is encrypted both when it is transferred and when it is stored.
Data minimisation
Only what is actually needed is collected, nothing more.
Right to erasure
Data is deleted on request and the customer keeps control.
Neutrality
Forsio sells no insurance and favours no insurer.
EU endpoints for sensitive data
Sensitive information used for document analysis is processed through model endpoints inside the EU.
Forsio claims no certifications it does not hold.
The processing of insurance information, individual rights and subprocessors are described in the product privacy policy (in Swedish). Website privacy policy (Swedish).
How the documents are read
A model reads. The reference makes it checkable.
Insurance terms are text, and it is a language model that reads them. That is why the analysis comes with traceability built in rather than asking to be taken on trust.
Every value carries its source
An amount or a deductible read out of a document can show the passage it came from. Where it cannot, that is stated outright. The value is then not source-verified.
Sensitive data stays inside the EU
Sensitive information, such as health information, is processed through model endpoints inside the EU when documents are analysed.
A basis, not an answer
The analysis can be incomplete and says so itself. It is made to be checked against the documents, not to replace them.
Questions about how we handle data?
Get in touch and we will go through what you need to know. We reply within three working days.
Forsio is not an insurance intermediary and does not provide insurance advice.