WYEA / Security / Vendor review

Vendor review

Send us your vendor questionnaire. We answer it in writing.

WYEA builds firm-owned document engines for specialty insurers, MGAs and program administrators. Below are the controls insurers are asked to require of service providers, the source for each, and where we stand today, including what we do not have yet.

Last reviewed

The table

Requirement, source, and where we stand

A row reads "Ask us" until the answer is confirmed in writing. Ask, and you will get the current position in writing.

RequirementSourceWYEA todayStatus
Access controls and MFA 23 NYCRR 500.11(b)(1)62% of security teams require MFA from vendors, 73% in financial services (ISC2 2025) Own sign-in per insurer, federated to the insurer's identity provider Ask usUntil MFA enforcement is confirmed
Encryption in transit and at rest 23 NYCRR 500.11(b)(2) At rest: stated on /security. In transit: not stated Ask usUntil both are confirmed
Notice of a cybersecurity event 23 NYCRR 500.11(b)(3)61% require incident response and breach notification, 75% in financial services (ISC2 2025) Not stated Ask usUntil a notice window is set for the MSA
Security representations and warranties 23 NYCRR 500.11(b)(4) Not stated Ask usUntil offered in the MSA
Standards compliance: SOC 2, ISO 27001, NIST 77% name it their top vendor requirement, 84% in financial services (ISC2 2025) None Not heldStays on the not-claimed list
Independent audit or penetration test 71% require audits or attestations, 80% in financial services (ISC2 2025) None Not heldStays on the not-claimed list
No training on client content wyea.ai/security Contractual and architectural Holds today
Data isolation wyea.ai/security One system per insurer, with its own database, network and sign-in Holds today

Not held

What a reviewer will not find yet

The same list as the security page. An item leaves it only when the thing exists.

  • SOC 2 report, ISO 27001 certificate

    There is no report or certificate to hand you.

    Not held
  • Independent penetration test

    No third-party test has been run.

    Not held
  • Hosting in your own cloud or on premises

    Each system runs on our infrastructure.

    Not built
  • Customer-managed keys

    Keys you hold and can revoke independently of us are not offered.

    Not built
  • Automated export and deletion

    Offboarding is run with you by hand and confirmed in writing.

    Not built
  • A log of our support access that you can read

    Support access is scoped and limited, and not yet visible to you.

    Not built

Sources

  1. 23 NYCRR 500.11, third-party service provider security policy, New York Department of Financial Services cybersecurity regulation, via the Legal Information Institute.
  2. 2025 ISC2 Supply Chain Risk Survey, ISC2, November 2025.

Your questionnaire

Send it to us. We answer in writing.

Use the form, or book a call and bring your security team.

Prefer to write? We reply within one business day.