← Home
Agency Command Center

Security

Agency Command Center — Strevolve LLC

Last updated: June 26, 2026

Independent insurance agents trust Agency Command Center with their client lists, policy records, renewal calendars, and business communications. We take that responsibility seriously. This page describes how we protect your data and the data you enter about your clients.

If you have a security concern or question not addressed here, contact us at [email protected].

Data Encryption

All data transmitted between your browser or device and our servers is encrypted using TLS 1.2 or higher. This applies to every page of the app, every API call, every email action, and every file upload or download. There are no unencrypted connections to the Platform.

All data stored in our database is encrypted at rest. This includes your client records, policy data, voice memo transcripts, compliance logs, account information, and all other data you enter into the Platform.

Voice memo audio files are stored encrypted and deleted automatically after 90 days.

Data Isolation — Row-Level Security

Every organization's data in Agency Command Center is isolated at the database level using row-level security (RLS) policies. This means your client records, policy data, and account information are inaccessible to any other organization's account — not just hidden in the UI, but blocked at the database query level.

When you log in, you see only your organization's data. When a producer you have invited logs in, they see only the data their role permits within your organization. No other organization can access your data regardless of how they query the system.

Access Controls

Access to your data is restricted to:

  • Your account and any producers you have invited under an Agency subscription, subject to the role you assigned them.
  • Strevolve team members who access account data only as necessary to provide support or maintain the Platform. Access is logged and reviewed.
  • Third-party sub-processors listed in our Privacy Policy, each of which processes data only as necessary to provide their specific service.

We do not share your data with any other party. We do not sell your data. We do not use your client data for any purpose other than providing you the service.

Authentication and Session Security

Account access requires email and password authentication managed through Supabase Auth. Passwords are hashed and never stored in plain text.

Agency producers invited to your account authenticate via Supabase's invitation flow and set their own password independently.

Client portal access — available to Producer and Agency tier subscribers — uses one-time verification codes sent to the client's email address. Client sessions are separate from agent sessions and have no access to agent-level data.

All sessions use secure, HTTP-only cookies. Sessions expire after 30 days of inactivity and require re-authentication.

Infrastructure Security

Agency Command Center is hosted on infrastructure provided by Supabase, which runs on AWS. Network traffic is routed through Cloudflare, which provides DDoS protection, bot mitigation, and TLS termination.

We do not manage physical servers. Infrastructure security at the hardware and data center level is handled by our hosting providers, each of which maintains their own security certifications and compliance programs.

Sub-Processor Security

Agency Command Center relies on the following sub-processors to operate. Each is a recognized provider with its own security program:

  • Supabase — database, authentication, and file storage. Supabase is SOC 2 Type II certified.
  • Stripe — payment processing. Stripe is PCI DSS Level 1 certified, the highest level of payment security certification.
  • Resend — transactional email delivery. Resend operates on AWS infrastructure with encryption in transit and at rest.
  • Cloudflare — DNS, network security, and content delivery. Cloudflare maintains SOC 2 Type II certification.
  • Anthropic — AI content generation via API. Prompts sent to Anthropic for content generation do not include your client data — only the content generation context you provide.

A full list of sub-processors and links to their privacy policies is available in our Privacy Policy at theagencycommandcenter.net/privacy.

Compliance Logs and Audit Data

If you have an active Helm subscription, the Platform maintains a compliance audit log recording every compliance review decision made on your content. This log is retained for three years from the date of each entry as part of our regulatory-ready service commitment.

Compliance logs are stored with the same encryption and access controls as all other account data. Only you and authorized members of your organization can access your compliance log.

Data Retention and Deletion

  • Account and client data — retained while your account is active, then archived for 90 days after cancellation, then permanently deleted.
  • Voice memo audio — deleted after 90 days from upload.
  • Compliance audit logs — retained for three years from date of entry.
  • Billing records — retained for seven years as required by financial recordkeeping law.

You may request deletion of your account and data at any time by contacting [email protected]. We will process deletion requests within 30 days. Compliance audit logs subject to the three-year retention requirement cannot be deleted on request prior to expiration.

You can export your client and policy data at any time from Settings.

Security Incidents

In the event of a security incident that affects your data, we will notify you by email within 72 hours of becoming aware of the incident. The notification will describe the nature of the incident, what data was affected, what we have done in response, and what steps you can take to protect yourself.

To report a suspected security vulnerability or incident, contact us immediately at [email protected] with the subject line: Security Issue.

What We Are Working Toward

We are a founder-stage company. We have implemented the security controls described on this page and we believe they are appropriate for the current stage of the product. We have not yet pursued formal third-party security certifications such as SOC 2 Type II for Strevolve LLC directly — this is on our roadmap as the company grows.

We believe in transparency about where we are. If you have specific security requirements that go beyond what is described here, contact us before purchasing and we will give you an honest answer about whether ACC meets your needs.

Contact

Security questions or concerns:

[email protected]

Strevolve LLC
30 N Gould St Ste N
Sheridan, WY 82801

Agency Command Center™ and Helm™ are trademarks of Strevolve LLC. All rights reserved.

© 2026 Strevolve LLC