SECURITY AND COMPLIANCE

Security You Can Check Against the Reports

VCA Software is SOC 1 and SOC 2 certified, each Type 1 and Type 2, after an independent audit by Prescient Assurance in 2026. The questions that come next are answered below, and anything not yet published says so.

Written for the reviewer completing a third-party security questionnaire on VCA ClaimsCore. Evaluating the software itself? Start with the Platform →

INDEPENDENT ASSURANCE

Type 1Controls as designed, on a single day
Type 2Controls tested over a period of time
SOC 1Controls that bear on your financial reporting
SOC 1 Type 1Certified 2026
SOC 1 Type 2Certified 2026
SOC 2Trust services criteria, security first
SOC 2 Type 1Certified 2026
SOC 2 Type 2Certified 2026
AICPA SOC for Service Organizations, about SOC reports at aicpa.org

Independent Audit Prescient Assurance

What to Read in the Reports

THE REVIEW AT A GLANCE

Your Questionnaire, Row by Row

What VCA publishes comes first, each row linked to the detail behind it. What is settled for your environment in the review comes after, and the status says which is which.

SOC Certified tested in the independent audit behind the SOC reportsStated by VCA VCA's own statementConfirmed in Your Review answered for your environmentBring to the Review belongs in your agreementTable last reviewed October 2026
QuestionVCA's AnswerStatus
Published by VCA
Independent AssuranceFour reports: SOC 1 and SOC 2, Type 1 and Type 2, one auditorSOC Certified
EncryptionClient data is encrypted in transit and at restStated by VCA
Access ControlSet per status and action, recorded on the claimStated by VCA
Sign-InYour company can require multi-factor authentication and enforce password strength and rotationStated by VCA
Single Sign-OnVCA supports single sign-on (SSO)Stated by VCA
Authority and ReservesAuthority limits per client or per program, and each reserve movement recorded with who made itStated by VCA
ClaimsAI™ GovernanceEvery draft attributed and logged, and nothing enters the claim until a person accepts itby the end of 2026
Access From Outside Your TeamWith the ClientPortal add-on, access is granted per client representative and set by company, claim and tabStated by VCA
Your Claims Data, in Your Own SystemsWith the DataBridge add-on, your claims data is delivered out of VCA into your own data warehouse or BI tool, with encrypted delivery, on a schedule you setStated by VCA
Hosting and ResidencyHosted in four regions: the US, Canada, the UK and Australia. The region for your environment is confirmed in the reviewStated by VCA
Data Separation Between ClientsOne client's claims can't be seen in another client's views or reportsStated by VCA
Getting the ReportsSOC 2 Type 2 shared under NDA, including during an evaluation; SOC 1 Type 2 for clients and their auditors. Your security or vendor-risk team requests them from info@vcasoftware.comStated by VCA
Settled for Your Environment in the Review
Business Continuity and Disaster RecoveryRecovery objectives and how recovery is tested are answered in the reviewConfirmed in Your Review
Penetration Testing and Vulnerability ManagementScope and cadence are answered in the reviewConfirmed in Your Review
SubprocessorsAny third parties that handle your claims data are named in the reviewConfirmed in Your Review
ClaimsAI and Your DataHow ClaimsAI handles and keeps the claims data it reads is answered in the reviewConfirmed in Your Review
Incident NotificationWho tells you, how and how fast belongs in writing in your agreementBring to the Review
Service LevelsService levels are set in each client's agreementBring to the Review
Data ReturnNot published. The format, timeline and cost belong in writing in your agreementBring to the Review

INDEPENDENT ASSURANCE

What the SOC Reports Let You Check

A Type 1 report is a snapshot, a description of controls as they stood on a single day. A Type 2 examination tests how those controls operated over a period of time. It is the difference between saying you lock the door and showing the log of every night the door was locked.

SOC 1 reports on controls that bear on your financial reporting, which matters where claim payments and reserves reach your books. SOC 2 reports on controls against the trust services criteria, security first among them.

A questionnaire answer should come from the report, not from this page. Read two things in it before the box gets ticked:

  • The scope. Which criteria were in scope and which period the examination covered are both stated in the report.
  • The exceptions. A Type 2 report lists any test exceptions the auditor found and how management responded.
AICPA SOC for Service Organizations, about SOC reports at aicpa.org

THE REPORTS

Ask for the reports

VCA shares its SOC 2 Type 2 report under NDA, including with companies still evaluating VCA, and its SOC 1 Type 2 report with clients and their financial-statement auditors. Ask from your security or vendor-risk team and name the framework your review follows.

info@vcasoftware.com

Read the Announcement →

ACCESS AND AUDIT TRAIL

Who Can Act on a Claim, and the Record of It

Auditors, carrier clients and regulators all ask who could do what on a claim, and what was done. VCA goes deep in claims, so the controls sit where claims risk sits: authority, reserves and payments, each recorded on the claim as the work happens.

  • Permissions and Sign-InPermissions are set down to individual statuses and actions. VCA supports single sign-on (SSO), and your company can require multi-factor authentication at sign-in and enforce password strength and rotation. The claim records who did what and when; notes and documents are timestamped on it, and email sent from it goes through your own mail server and is logged to it.
  • Authority per Client or ProgramAuthority limits are configured per client or per program, and ClaimsCore tracks the authority protocols and reporting requirements attached to them. One client's claims can't be seen in another client's views or reports. Transactional reserve history records each reserve movement, who made it and which fund account it came from.
  • ClaimsAI Drafts, AttributedA ClaimsAI draft carries who drafted it and who reviewed it, and that line is written to the claim's activity log. Nothing it produces enters the claim until a person accepts it, and the claims professional decides. ClaimsAI arrives by the end of 2026.How ClaimsAI Is Applied →
  • Client Access, with the ClientPortal Add-OnPortal access is granted per client representative and set by company, by claim, by Lloyd's classification and by tab. Notes marked Internal stay off the portal, and access is role-based, with an access record.About ClientPortal →

FOR THE AGREEMENT

Three Terms to Get in Writing

Ask VCA for each of these in your agreement, and ask the same of every vendor you compare.

Send Us the Questionnaire

Your Security Contact and Notification Path

Clients reach VCA at clientservices@vcasoftware.com. Ask who owns security questions once you are live, and what you are told, and when, if something happens.

Your Claims Data at the End of the Term

The format, the timeline and the cost of returning your claims data when the agreement ends.

Service Levels

Service levels are set in each client's agreement. Ask for yours to state uptime, support response times, backup cadence and service credits.

DELEGATED AUTHORITY

When Your Review Answers to a Managing Agent

Lloyd's Principle 4, claims management, became a hurdle Principle on January 1, 2026. The Principles bind managing agents, and delegated claims administrators (DCAs) and coverholders carry it through the managing agent's oversight, audit, and reporting requirements.

How VCA Supports Delegated Authority

THE EVIDENCE

For a managing agent, VCA records every reserve change, contact and payment its delegated administrators make, in structured data, the day it happens, in the form Principle 4 asks for.

VCA's three-part white-paper series Proof, Not Attestation, written by Chief Product Officer Ilda Cairns, covers what Principle 4 requires and how to evidence compliance.

Read the Series →

Questions a Security Review Asks

Is VCA SOC 1 and SOC 2 certified?

Yes. VCA Software is SOC 1 and SOC 2 certified, each Type 1 and Type 2, after an independent audit by Prescient Assurance in 2026. Formally, a SOC report is an attestation: the independent auditor's opinion on VCA's controls, not a certificate a vendor awards itself. Ask for the reports to read the opinion, the scope and the period they cover.

How do we get the SOC reports?

Email info@vcasoftware.com from your security or vendor-risk team and say what your review covers. VCA shares its SOC 2 Type 2 report under NDA, including with companies still evaluating VCA. The SOC 1 Type 2 report goes to clients and their financial-statement auditors.

Where is VCA hosted, and where does our data reside?

VCA is hosted in four regions: the US, Canada, the UK and Australia. The region for your environment is confirmed in the security review, so if data residency decides the deal, raise it at the start.

Does VCA use AI, and who is accountable for what it produces?

Yes. ClaimsAI works inside the claim: it finds, summarizes and drafts, and the claims professional decides, approves, sets reserves and authorizes payments. Each draft carries who drafted it and who reviewed it, and that line is written to the claim's activity log. ClaimsAI arrives by the end of 2026.

Can we get our claims data out of VCA?

While you are a client, the DataBridge add-on delivers your claims data out of VCA into your own data warehouse or BI tool, as structured extracts in a standardized data model, on a schedule you set: hourly, daily or weekly. What VCA returns when the agreement ends, in what format, how fast and at what cost, is not published here. Get it in writing in the agreement.

Which clients and programs run on VCA?

Named clients run their claims on VCA ClaimsCore from different seats. TWICO runs it as a carrier and TELUS as a self-insured organization. Accelerant, Hadron and Thomas Miller run program business on it, and PIB runs it as a third-party administrator.

What does VCA Software sell?

Claims management software, and only claims management software. VCA has no adjusting arm, no TPA division and no claims services business. The review covers VCA ClaimsCore and the add-ons you license with it.

Bring us a claim where the promise was hard to keep

Walk through the rows this page marks for the review on a call with VCA and your security team.

Request a Demo

Send Us the Questionnaire →