Your banking system data is sensitive. Policy Stack is built with security at the infrastructure level — not as an afterthought.
Field-Level Encryption
Every financial value in Policy Stack is encrypted at the field level before it is stored in the database. This means that even at the database layer, financial values are not stored as plain text.
Encrypted fields include:
- Cash value amounts
- Death benefit amounts
- Loan balances
- Premium amounts
- Deployment values and return rates
- Cash flow amounts
- All other financial figures across policies, loans, deployments, and snapshots
Field-level encryption happens in the application using AES-256-GCM before values are stored. Each encryption operation uses a unique initialization vector, while the versioned encryption key is held in protected server configuration. The database stores ciphertext, not plaintext financial values.
Field-level encryption is distinct from transport encryption (HTTPS). HTTPS protects data in transit — between your browser and Policy Stack's servers. Field-level encryption protects data at rest — in the database itself. Policy Stack applies both.
Row-Level Security (RLS)
Policy Stack uses row-level security to scope customer-data queries made through authenticated user sessions. RLS is a database-level enforcement mechanism that limits rows to the authorized account or collaboration relationship.