← carrierbasis.com

Security

Updated August 3, 2026

CarrierBasis exists to produce records a brokerage may one day need to stand behind. That only works if the data underneath is protected and the records themselves can be trusted. This page describes how we approach both.

Certified infrastructure

CarrierBasis is hosted entirely on infrastructure whose providers hold SOC 2 Type 2 attestations and ISO 27001 certifications — covering our application hosting, database, file storage, AI processing, and error monitoring. To be precise about what that claim means: those certifications belong to our infrastructure providers and cover the platforms the Service runs on; NewWay Digital does not itself hold these certifications. We select providers on this basis deliberately, and we're glad to identify our current providers and their certifications to customers on request.

Encryption

Tenant isolation

CarrierBasis is multi-tenant, and isolation is enforced at the database layer: every tenant-owned record is protected by row-level security policies keyed to the authenticated tenant, so one brokerage's data is not reachable from another's session — including by our own background processing, which operates under the same tenant-scoped controls as an ordinary request.

Who did what: authenticated identity

Users sign in with individual accounts. Actions that matter — resolving a finding, recording the basis for a decision, approving, sealing — are attributed to the authenticated user who performed them, and administrative changes to a brokerage's policy settings are restricted to that brokerage's administrators.

Record integrity

When a compliance record is approved, it is locked and fingerprinted with a SHA-256 hash. The fingerprint is stored with the record, enabling later verification that the record's contents have not changed since sealing. Records are never edited after sealing, and prior determinations are never rewritten — they can only be superseded by new, dated entries that reference what they replace.

Data practices

Operational monitoring

So that failures are noticed quickly rather than discovered later, CarrierBasis reports application errors to a third-party error-monitoring service. What that service receives is deliberately narrow: the error, the operation that produced it, and identifiers such as a brokerage's tenant identifier or an internal record id — not the records those identifiers point to. Carrier data, policy settings, documents, and sealed record contents are not sent. Authorization headers, API keys, tokens, passwords and stored credentials are stripped before anything leaves the platform.

Our error-monitoring provider holds SOC 2 Type 2 and ISO 27001 certifications and processes this data under a data processing agreement. Error monitoring observes the Service; it is never a path by which a record can be altered.

Reporting a vulnerability

If you believe you've found a security issue in the Site or Service, please email contact@workanewway.com with "Security report" in the subject. We appreciate good-faith reports and will respond promptly. Please don't access data that isn't yours or disrupt the Service while investigating.

Questions

Security questionnaires and customer-specific questions: contact@workanewway.com.