SECURITY AND COMPLIANCE
Security You Can Check Against the Reports
VCA Software is SOC 1 and SOC 2 certified, each Type 1 and Type 2, after an independent audit by Prescient Assurance in 2026. The questions that come next are answered below, and anything not yet published says so.
Written for the reviewer completing a third-party security questionnaire on VCA ClaimsCore. Evaluating the software itself? Start with the Platform →
INDEPENDENT ASSURANCE
THE REVIEW AT A GLANCE
Your Questionnaire, Row by Row
What VCA publishes comes first, each row linked to the detail behind it. What is settled for your environment in the review comes after, and the status says which is which.
| Question | VCA's Answer | Status |
|---|---|---|
| Published by VCA | ||
| Independent Assurance | Four reports: SOC 1 and SOC 2, Type 1 and Type 2, one auditor | SOC Certified |
| Encryption | Client data is encrypted in transit and at rest | Stated by VCA |
| Access Control | Set per status and action, recorded on the claim | Stated by VCA |
| Sign-In | Your company can require multi-factor authentication and enforce password strength and rotation | Stated by VCA |
| Single Sign-On | VCA supports single sign-on (SSO) | Stated by VCA |
| Authority and Reserves | Authority limits per client or per program, and each reserve movement recorded with who made it | Stated by VCA |
| ClaimsAI™ Governance | Every draft attributed and logged, and nothing enters the claim until a person accepts it | by the end of 2026 |
| Access From Outside Your Team | With the ClientPortal add-on, access is granted per client representative and set by company, claim and tab | Stated by VCA |
| Your Claims Data, in Your Own Systems | With the DataBridge add-on, your claims data is delivered out of VCA into your own data warehouse or BI tool, with encrypted delivery, on a schedule you set | Stated by VCA |
| Hosting and Residency | Hosted in four regions: the US, Canada, the UK and Australia. The region for your environment is confirmed in the review | Stated by VCA |
| Data Separation Between Clients | One client's claims can't be seen in another client's views or reports | Stated by VCA |
| Getting the Reports | SOC 2 Type 2 shared under NDA, including during an evaluation; SOC 1 Type 2 for clients and their auditors. Your security or vendor-risk team requests them from info@vcasoftware.com | Stated by VCA |
| Settled for Your Environment in the Review | ||
| Business Continuity and Disaster Recovery | Recovery objectives and how recovery is tested are answered in the review | Confirmed in Your Review |
| Penetration Testing and Vulnerability Management | Scope and cadence are answered in the review | Confirmed in Your Review |
| Subprocessors | Any third parties that handle your claims data are named in the review | Confirmed in Your Review |
| ClaimsAI and Your Data | How ClaimsAI handles and keeps the claims data it reads is answered in the review | Confirmed in Your Review |
| Incident Notification | Who tells you, how and how fast belongs in writing in your agreement | Bring to the Review |
| Service Levels | Service levels are set in each client's agreement | Bring to the Review |
| Data Return | Not published. The format, timeline and cost belong in writing in your agreement | Bring to the Review |
INDEPENDENT ASSURANCE
What the SOC Reports Let You Check
A Type 1 report is a snapshot, a description of controls as they stood on a single day. A Type 2 examination tests how those controls operated over a period of time. It is the difference between saying you lock the door and showing the log of every night the door was locked.
SOC 1 reports on controls that bear on your financial reporting, which matters where claim payments and reserves reach your books. SOC 2 reports on controls against the trust services criteria, security first among them.
A questionnaire answer should come from the report, not from this page. Read two things in it before the box gets ticked:
- The scope. Which criteria were in scope and which period the examination covered are both stated in the report.
- The exceptions. A Type 2 report lists any test exceptions the auditor found and how management responded.
THE REPORTS
Ask for the reports
VCA shares its SOC 2 Type 2 report under NDA, including with companies still evaluating VCA, and its SOC 1 Type 2 report with clients and their financial-statement auditors. Ask from your security or vendor-risk team and name the framework your review follows.
ACCESS AND AUDIT TRAIL
Who Can Act on a Claim, and the Record of It
Auditors, carrier clients and regulators all ask who could do what on a claim, and what was done. VCA goes deep in claims, so the controls sit where claims risk sits: authority, reserves and payments, each recorded on the claim as the work happens.
- Permissions and Sign-InPermissions are set down to individual statuses and actions. VCA supports single sign-on (SSO), and your company can require multi-factor authentication at sign-in and enforce password strength and rotation. The claim records who did what and when; notes and documents are timestamped on it, and email sent from it goes through your own mail server and is logged to it.
- Authority per Client or ProgramAuthority limits are configured per client or per program, and ClaimsCore tracks the authority protocols and reporting requirements attached to them. One client's claims can't be seen in another client's views or reports. Transactional reserve history records each reserve movement, who made it and which fund account it came from.
- ClaimsAI Drafts, AttributedA ClaimsAI draft carries who drafted it and who reviewed it, and that line is written to the claim's activity log. Nothing it produces enters the claim until a person accepts it, and the claims professional decides. ClaimsAI arrives by the end of 2026.How ClaimsAI Is Applied →
- Client Access, with the ClientPortal Add-OnPortal access is granted per client representative and set by company, by claim, by Lloyd's classification and by tab. Notes marked Internal stay off the portal, and access is role-based, with an access record.About ClientPortal →
FOR THE AGREEMENT
Three Terms to Get in Writing
Ask VCA for each of these in your agreement, and ask the same of every vendor you compare.
Your Security Contact and Notification Path
Clients reach VCA at clientservices@vcasoftware.com. Ask who owns security questions once you are live, and what you are told, and when, if something happens.
Your Claims Data at the End of the Term
The format, the timeline and the cost of returning your claims data when the agreement ends.
Service Levels
Service levels are set in each client's agreement. Ask for yours to state uptime, support response times, backup cadence and service credits.
DELEGATED AUTHORITY
When Your Review Answers to a Managing Agent
Lloyd's Principle 4, claims management, became a hurdle Principle on January 1, 2026. The Principles bind managing agents, and delegated claims administrators (DCAs) and coverholders carry it through the managing agent's oversight, audit, and reporting requirements.
THE EVIDENCE
For a managing agent, VCA records every reserve change, contact and payment its delegated administrators make, in structured data, the day it happens, in the form Principle 4 asks for.
VCA's three-part white-paper series Proof, Not Attestation, written by Chief Product Officer Ilda Cairns, covers what Principle 4 requires and how to evidence compliance.
Questions a Security Review Asks
Is VCA SOC 1 and SOC 2 certified?
Yes. VCA Software is SOC 1 and SOC 2 certified, each Type 1 and Type 2, after an independent audit by Prescient Assurance in 2026. Formally, a SOC report is an attestation: the independent auditor's opinion on VCA's controls, not a certificate a vendor awards itself. Ask for the reports to read the opinion, the scope and the period they cover.
How do we get the SOC reports?
Email info@vcasoftware.com from your security or vendor-risk team and say what your review covers. VCA shares its SOC 2 Type 2 report under NDA, including with companies still evaluating VCA. The SOC 1 Type 2 report goes to clients and their financial-statement auditors.
Where is VCA hosted, and where does our data reside?
VCA is hosted in four regions: the US, Canada, the UK and Australia. The region for your environment is confirmed in the security review, so if data residency decides the deal, raise it at the start.
Does VCA use AI, and who is accountable for what it produces?
Yes. ClaimsAI works inside the claim: it finds, summarizes and drafts, and the claims professional decides, approves, sets reserves and authorizes payments. Each draft carries who drafted it and who reviewed it, and that line is written to the claim's activity log. ClaimsAI arrives by the end of 2026.
Can we get our claims data out of VCA?
While you are a client, the DataBridge add-on delivers your claims data out of VCA into your own data warehouse or BI tool, as structured extracts in a standardized data model, on a schedule you set: hourly, daily or weekly. What VCA returns when the agreement ends, in what format, how fast and at what cost, is not published here. Get it in writing in the agreement.
Which clients and programs run on VCA?
Named clients run their claims on VCA ClaimsCore from different seats. TWICO runs it as a carrier and TELUS as a self-insured organization. Accelerant, Hadron and Thomas Miller run program business on it, and PIB runs it as a third-party administrator.
What does VCA Software sell?
Claims management software, and only claims management software. VCA has no adjusting arm, no TPA division and no claims services business. The review covers VCA ClaimsCore and the add-ons you license with it.
Bring us a claim where the promise was hard to keep
Walk through the rows this page marks for the review on a call with VCA and your security team.
Request a Demo
