WYEA / Security / Vendor review
Vendor review
Send us your vendor questionnaire. We answer it in writing.
WYEA builds firm-owned document engines for specialty insurers, MGAs and program administrators. Below are the controls insurers are asked to require of service providers, the source for each, and where we stand today, including what we do not have yet.
Last reviewed
The table
Requirement, source, and where we stand
A row reads "Ask us" until the answer is confirmed in writing. Ask, and you will get the current position in writing.
| Requirement | Source | WYEA today | Status |
|---|---|---|---|
| Access controls and MFA | 23 NYCRR 500.11(b)(1)62% of security teams require MFA from vendors, 73% in financial services (ISC2 2025) | Own sign-in per insurer, federated to the insurer's identity provider | Ask usUntil MFA enforcement is confirmed |
| Encryption in transit and at rest | 23 NYCRR 500.11(b)(2) | At rest: stated on /security. In transit: not stated | Ask usUntil both are confirmed |
| Notice of a cybersecurity event | 23 NYCRR 500.11(b)(3)61% require incident response and breach notification, 75% in financial services (ISC2 2025) | Not stated | Ask usUntil a notice window is set for the MSA |
| Security representations and warranties | 23 NYCRR 500.11(b)(4) | Not stated | Ask usUntil offered in the MSA |
| Standards compliance: SOC 2, ISO 27001, NIST | 77% name it their top vendor requirement, 84% in financial services (ISC2 2025) | None | Not heldStays on the not-claimed list |
| Independent audit or penetration test | 71% require audits or attestations, 80% in financial services (ISC2 2025) | None | Not heldStays on the not-claimed list |
| No training on client content | wyea.ai/security | Contractual and architectural | Holds today |
| Data isolation | wyea.ai/security | One system per insurer, with its own database, network and sign-in | Holds today |
Not held
What a reviewer will not find yet
The same list as the security page. An item leaves it only when the thing exists.
-
SOC 2 report, ISO 27001 certificateNot held
There is no report or certificate to hand you.
-
Independent penetration testNot held
No third-party test has been run.
-
Hosting in your own cloud or on premisesNot built
Each system runs on our infrastructure.
-
Customer-managed keysNot built
Keys you hold and can revoke independently of us are not offered.
-
Automated export and deletionNot built
Offboarding is run with you by hand and confirmed in writing.
-
A log of our support access that you can readNot built
Support access is scoped and limited, and not yet visible to you.
Sources
- 23 NYCRR 500.11, third-party service provider security policy, New York Department of Financial Services cybersecurity regulation, via the Legal Information Institute.
- 2025 ISC2 Supply Chain Risk Survey, ISC2, November 2025.
Your questionnaire
Send it to us. We answer in writing.
Use the form, or book a call and bring your security team.
Thanks. Your message is on its way. We'll reply within one business day.