Built for Regulated Industries

Enterprise-grade security isn't an add-on — it's the foundation. Built by a team that's done this before — at Fieldglass (acquired by SAP), divvyDOSE (acquired by Optum), and Catalytic (acquired by PagerDuty).

View Trust Portal
Architecture

Single-Tenant by Default

Your data never touches another customer's environment.

Isolated Environments

Dedicated processing pipelines from ingestion through intelligence extraction. No shared infrastructure, no commingled data.

Zero-Credential Architecture

No passwords stored. Token-based OAuth 2.0 with automatic renewal. IP allowlisting for API access.

Encryption Everywhere

Data encrypted at rest and in transit. TLS 1.2+ for all connections. AES-256 for stored data.

Data Handling

Your Data Is Yours Alone

Clear rules about what we process, how we process it, and what we never do.

No AI Training

We never use customer data to train our foundational models. Your claims data is used solely to serve your operation.

Retention Controls

Zero-day retention is the default for all foundation model interactions. You control data retention and deletion policies for your claims data.

Processing Transparency

Every document processed is logged with what was extracted, what signals were evaluated, and what actions were taken.

Compliance & Certifications

Enterprise-Grade from Day One

Built for carriers, MGAs, and TPAs with strict data governance requirements.

SOC 2 Type II

Continuous compliance monitoring via Vanta. Audited controls across security, availability, and confidentiality.

BAA Coverage

Business Associate Agreements available for workflows involving protected health information.

Regulatory Alignment

Aligned with NAIC Model Bulletin on AI Systems and NIST AI Risk Management Framework.

View live audit status
AI Governance

Responsible AI in Regulated Workflows

Most vendors don't address how their AI makes decisions, how it fails, or how every action is auditable. We do.

Fail-Safe by Design

Uncertainty triggers human review, not silent approval. The system routes to judgment when confidence is low — it never guesses.

Explainable Outputs

Every finding includes the evidence that triggered it — the specific language, the document, the page. No black-box decisions.

No Hallucination-Dependent Decisions

Isomer's risk signals are evaluated against structured detection logic, not open-ended generation. Signals are matched, not imagined.

Complete Decision Audit Trail

Every AI call logged. Every signal evaluation recorded. Every action traceable. Ready for regulatory review at any time.

Audit & Observability

Prove What Happened and Why

Complete operational transparency for compliance teams, regulators, and internal review.

Signal History

Complete record of every signal detected, confidence level, and classification — across every communication.

Action Logs

Every notification sent, workflow triggered, and system updated — with timestamps and context.

Exportable Reports

Audit trails exportable for regulatory filings, market conduct exams, and internal compliance reviews.

Integration Security

You Choose the Access Level

We don't require admin access to your systems. You define the connection method and the permissions.

OAuth 2.0

Token-based authentication with automatic renewal. No passwords stored or transmitted.

Read-Only Options

Risk detection operates with read-only access. We never send, modify, or delete your data.

API Authentication

API key and IP allowlisting for programmatic integrations. Scoped permissions per endpoint.

Enterprise Readiness

Ready for Your Scale and Your Requirements

Isomer is built for enterprise deployment from day one — not retrofitted.

Weeks, Not Months

Production deployment in weeks. No data migration, no core system changes required.

Dedicated Environments

Every customer gets their own processing infrastructure. No multi-tenant resource contention.

Direct Support

Dedicated specialists with direct Slack or Teams channels. No ticket queues, no chatbots.

See Our Security Posture

Visit our trust portal for live audit status, or schedule a security review call.