Trust Center
We Earn Your Trust Every Day
Security, privacy, and compliance aren't features — they're foundations. Here's how Patriots Protect protects the people who protect us.
Our Five Pillars of Trust
Community Verification
- Verification toggle — admin-controlled, default OFF (honor system)
- When enabled: military ID, badge, or official documentation required
- Members receive a shield badge on their profile
- Community self-policing: members can report bad actors
- Founding members get first-access and priority community status
- Your verification data is never sold or shared outside Patriots Protect
Data Security
- AES-256 encryption at rest and in transit
- SOC 2 Type II audit in progress
- Zero-trust architecture — no implicit trust
- Supabase Row Level Security on every table
- Regular penetration testing by third-party
- API keys stored in HashiCorp Vault — never in code
Privacy Commitment
- We never sell your personal data — ever
- Data minimization: we only collect what we need
- Right to deletion — request at any time
- CCPA and state privacy law compliant
- Your data leaves the US only with your consent
- Plain-English privacy policy (no legal jargon)
Regulatory Compliance
- TCPA compliant — written consent before all SMS
- Medicare marketing rule (CMS) compliant
- DNC list checked before every outbound call
- Licensed insurance professionals only
- State-by-state license verification
- FTC disclosure requirements met on all ads
Carrier Standards
- All carrier allies are A-rated or better
- No off-market or unlicensed products
- Commission disclosures on every quote
- Clawback policies communicated upfront
- No referral kickbacks that inflate prices
- Independent market comparison on every vertical
Where Your Data Goes
Complete transparency on our data flow — from the moment you fill out a form to the moment your policy is bound.
You submit a form
Your data is encrypted in transit (TLS 1.3) and stored in our Supabase PostgreSQL database with AES-256 encryption at rest.
Advisor assignment
Your assigned advisor is the only human who can access your profile. Our Row Level Security policy enforces this — no override possible.
Carrier outreach
Your advisor contacts the carriers you authorize. Only name, contact info, and coverage needs are shared — never your financial details.
Quote and bind
If you choose to bind a policy, the carrier handles their own data directly. Patriots Protect does not store payment information.
Ongoing relationship
You control your data. Download it, update it, or delete it anytime from your customer portal.
Frequently Asked Questions
Who can see my personal information?▾
Only your assigned advisor and our compliance team can access your data. We use Row Level Security to enforce this at the database level — it's not just policy, it's technical enforcement.
Do you sell or share my data with third parties?▾
No. We share your information only with the carrier(s) you authorize us to contact on your behalf — and only to request a quote. We never sell leads or personal data.
How do you handle SMS and calling compliance?▾
All SMS requires your explicit written consent (TCPA). We verify every phone number against national DNC registries and Twilio's carrier intelligence before dialing. Opt-out is instant: reply STOP to any message.
What happens to my data if I close my account?▾
You can request deletion of your account and all associated data at any time. We delete within 30 days and confirm via email. Regulatory records required by law are retained for the legally mandated period only.
Are your advisors licensed?▾
Yes. Every Patriots Protect advisor holds a valid insurance license in every state they serve. License numbers are available on request.
Questions About Your Data?
Our compliance team responds within 24 business hours. For immediate assistance, call our hero line.
