If you are running a vendor review, start here

You need to know what SnapLine does with submission data, what has been independently audited, and who to email to get the documents under NDA. This page answers the first two and gives you the route for the third.

Nothing here is a substitute for the certificates and the report, which are available on request.

What happens to a submission

SnapLine processes broker submissions: email bodies, PDF slips, spreadsheets, scanned documents and images. That data includes commercially sensitive terms and will frequently include personal data.

The processing path, in outline: a submission is received, documents are extracted, fields are read with their source regions recorded, an underwriter validates the record, and the structured output is made available downstream. The provenance link means the source document is retained as part of the record rather than discarded after extraction.

Your submission data does not train our models. We develop and evaluate against synthetic data. Customer submissions are processed to produce your records and are not used to train, fine-tune or improve any model, yours or anyone else’s.

Received

Email bodies, PDF slips, spreadsheets, scanned documents and images.

Includes commercially sensitive terms, and will frequently include personal data.

Processed
  1. 01Documents extractedFrom the bundle as received
  2. 02Fields readWith the source region recorded for each field
  3. 03An underwriter validates the recordA person confirms or corrects
  4. 04Structured output made available downstreamTo the systems you already run
Retained as part of the record

The structured record, and the source documents its fields were read from.

The provenance link means the source document is retained rather than discarded after extraction.

Boundary
Customer submissionsNot a model input
Synthetic dataWhat we develop and evaluate against
Model development and evaluation

Customer submissions are not used to train, fine-tune or improve any model, yours or anyone else’s.

The shape of the path, not its operating detail. Retention, hosting and access control are set out in the SOC 2 Type 2 report and the ISO certificates, which are available under NDA.

Independently audited

AWS PartnerGoogle for StartupsScoutInsurTech UKMGAA member

Lloyd's Lab Cohort 15 FinalistA selection. Not an accreditation, not a deployment, and not an endorsement by any syndicate.

The scope statement is the part that matters in a review, which is why we would rather leave it blank here than paraphrase it.

What to ask for

Current documentation lives in the trust centre, and access is gated. Name what you need in the first email. The usual list:

  • SOC 2 Type 2 report, under NDA
  • ISO/IEC 27001 certificate and Statement of Applicability
  • ISO/IEC 42001 certificate and scope statement
  • Data Processing Agreement
  • Completed security questionnaire, or our response to yours

If your review has a deadline, say so in the first email rather than the third.

Security and vulnerability reports go to security@genairate.io, which is monitored rather than forwarded to one person’s inbox.

Visit the trust centre

Start your security review

If you would rather have the conversation than the paperwork, book a call and bring whoever runs your third-party risk process.

Book a demo