SOPHIA XT

Insurance agencies

AI for insurance agencies, with policyholder data kept out.

Short answer

An insurance agency can use AI for quotes, renewals and claim letters if nonpublic personal information stays out of the AI provider's hands. Safe-Desk swaps Medicare numbers, health plan IDs, claim numbers, bank details and credit scores for placeholders before a message leaves, and reports each catch to the agency owner.

Updated September 24, 2026 · SOPHIA XT LLC

The risk

Producers and CSRs write renewal letters, claim updates and coverage summaries all day. The details that make those letters useful, such as policy and claim numbers, Medicare numbers and bank details for premium drafts, are the nonpublic personal information the agency is bound to protect.

The rules that apply

Gramm-Leach-Bliley Act. 15 U.S.C. 6801 obliges financial institutions, insurance agencies included, to protect the security and confidentiality of customers' nonpublic personal information. For insurers and producers, state insurance regulators enforce it.

NAIC Insurance Data Security Model Law (#668). The model law requires a licensee to keep an information security program based on a risk assessment, to oversee third-party service providers, and to investigate and report cybersecurity events. It applies only where your state has adopted it, and states have changed details, including small-agency exemptions. Your state insurance department can tell you what applies.

Agencies that sell health or Medicare products may hold health information, too. Safe-Desk does not sign a Business Associate Agreement, so check with your carrier or compliance advisor before using any AI tool with that information.

How Safe-Desk works in an agency

Staff keep using ChatGPT, Claude, Gemini, Copilot, Perplexity or DeepSeek. The Safe-Desk extension for Chrome and Edge, or the Safe-Desk Windows app for the ChatGPT, Claude and Copilot desktop apps, checks each message before it leaves. Client data becomes a placeholder such as [SSN_1], and only that version reaches the AI provider. When the answer comes back, the staff member who sent it sees the real values again; nobody else does. Passwords, keys and text marked privileged are stopped and sent nowhere. The owner gets a log of who sent what kind of data and which rule caught it, never the value itself, plus phone alerts and a monthly report. See how it works and the security page.

What the insurance template catches

Pick Insurance agencies at sign-up. The owner can change names, places and dates to off, flag or protect, and paste the client list so insureds' names are caught wherever they appear.

WhatWhat happens by default
Medicare number (MBI)Swapped for a placeholder and reported to the owner.
Health plan member IDSwapped for a placeholder and reported to the owner.
Claim numberSwapped for a placeholder and reported to the owner.
Insurance policy numberSwapped for a placeholder.
Vehicle VINSwapped for a placeholder.
Driver's license numberSwapped for a placeholder.
Bank routing numberSwapped for a placeholder and reported to the owner.
Bank account numberSwapped for a placeholder and reported to the owner.
Diagnosis codeSwapped for a placeholder and reported to the owner.
Credit scoreSwapped for a placeholder and reported to the owner.
Private keyStopped. Nothing is sent.
API key or access tokenStopped. Nothing is sent.
Login tokenStopped. Nothing is sent.
Password inside a linkStopped. Nothing is sent.
Password or PINStopped. Nothing is sent.
Payment card numberSwapped for a placeholder and reported to the owner.
ITIN (taxpayer number)Swapped for a placeholder and reported to the owner.
Social Security numberSwapped for a placeholder and reported to the owner.
Privileged or work-product materialStopped. Nothing is sent.
Date of birthSwapped for a placeholder.
Email addressSwapped for a placeholder.
Phone numberSwapped for a placeholder.
Names on your client listSwapped for a placeholder wherever they appear as written.
Other people's names, found from contextSwapped for a placeholder.
Addresses, found from contextSwapped for a placeholder.
Dates, found from contextSent as written and reported to the owner.
Custom topics the owner adds (a matter, a deal, a code name)Handled as the owner sets for each topic.

Read from the Insurance agencies template in the product. In strict mode, messages with identifiers such as SSNs and account numbers are stopped instead of swapped.

A worked example

Your staff type

Write a claim status email for client Linda Park, claim number CLM-2025-448812, Medicare number 1EG4-TE5-MK73, credit score 712.

The AI sees

Write a claim status email for client Linda Park, claim number [CLAIM_1], Medicare number [MEDICARE_ID_1], credit score [CREDIT_SCORE_1].

The owner's log

Sep 24, 2026, 2:14 PM UTC: Front desk. The message was sent. Swapped out: Medicare number (MBI), Claim number, Credit score.

The staff member reads the answer with the real values back in. The log names what kind of data was caught, never the values.

What it does not do

Safe-Desk does not make a firm compliant on its own and does not certify compliance. It has not been audited for SOC 2. It does not sign a Business Associate Agreement, so it is not for patient information. Names, addresses and dates are caught from your client list and from context; context detection is a best effort, because names have no checksum. Anything your firm sets to Flag is sent as written and reported to the owner.

Setup and price

Safe-Desk costs $19 per staff member a month, with a 14-day free trial. Each seat includes $5 of AI a month inside Safe-Desk, pooled across the firm, and AI beyond that is billed at the model's cost plus 30%. Using your own ChatGPT or Claude through the extension or the connector costs nothing extra. Optional setup: we set it up for $149 for up to 10 staff, $10 for each extra person.

Questions

Does GLBA apply to a small insurance agency?

GLBA covers financial institutions, and insurance agencies are among them. State insurance regulators enforce its privacy and security requirements for insurers and producers, and many states add their own data security law based on NAIC Model Law #668. Some states exempt the smallest licensees from parts of it.

Is Safe-Desk a third-party service provider under the model law?

Treat it as one. The gate reads each message in memory to check it. The security review covers storage, encryption, retention and subprocessors for your vendor file.

Can we use it for Medicare supplement or health plan work?

For everyday office work, yes, and it swaps Medicare numbers and health plan IDs by default. Safe-Desk does not sign a Business Associate Agreement, so do not submit protected health information to it.

Related

Try it at your firm.

Start free trialSee how it works

Safe-Desk costs $19 per staff member a month, with a 14-day free trial. Each seat includes $5 of AI a month inside Safe-Desk, pooled across the firm, and AI beyond that is billed at the model's cost plus 30%. Using your own ChatGPT or Claude through the extension or the connector costs nothing extra. Optional setup: we set it up for $149 for up to 10 staff, $10 for each extra person.