Industries / Insurance · insurers & health insurers
AI protection for insurers, built for Art. 35 VAG secrecy.
Secrecy under Art. 35 VAG, analogous to banking, and EU AI Act high-risk rules for life and health risk assessment and pricing from August 2026: the same workflow triggers both.
See it in action
Omnichannel protection, across all devices.
ChatGPT, Claude, Gemini, Copilot, DeepL and whatever your employees try next week: the same policies, anonymization and audit trail on the work laptop and the work phone.
See scenarios →Summarize the claim of Marco Rossi, policy KV-2291-0457, diagnosis: torn anterior cruciate ligament. Draft the benefits decision.
Summarize the claim of <PERSON>, policy <POLICY_NO>, diagnosis: <DIAGNOSIS>. Draft the benefits decision.
Here is the customer list:
Q3_Kundenliste.xlsx (2,400 rows)
NativeAI Guard, BLOCKED: Blocked attachment: Q3_Kundenliste.xlsx. Blocked by policy: Customer Data Leakage Prevention.
The AI governance framework for insurance
Six obligations. Here's our part, honestly.
We mark what NativeAI Guard solves for the channels we protect, where it contributes, and what stays with your processes.
Seen at Swiss insurers
An underwriter pastes a customer's medical history into an LLM to summarize a claim. Health data, a special category of personal data, just left the perimeter under the terms of service of a consumer product.
"How do we justify the decision of a fuzzy LLM classifier to the regulator?", the objection we hear from every insurance CISO. A block you cannot explain is a block you cannot defend.
Insurers are piloting AI agents that read claim submissions, medical reports and correspondence to triage claims. Those documents can carry a hidden prompt injection, and the agent's response can carry another claimant's health data out.
Writing policies in natural language instead of regex, that is the key differentiator of NativeAI Guard.
Policies, managed
The rulebook for insurers is already written. You adapt it.
Swiss DSG, GDPR and EU AI Act, plus your industry's specific duties. Security and compliance practitioners review it; we keep it current as the law changes.
During onboarding we tune the pack to your own data structures and internal rules, working from the compliance documents you already have.
Common questions
Frequently asked questions
Can the anonymized fields be restored in the model's answer, so the response is still usable?
Re-identification on the return path is in active development and does not ship today; it sits near the front of our development roadmap because several customers have asked for it. What works today: anonymization preserves context. Identifiers become typed placeholders, so the model still produces a useful, correctly structured answer that your people can complete internally.
How do we justify an AI-based blocking decision to a regulator? An LLM classifier looks fuzzy.
By making the decision reconstructable, not by claiming the model is infallible. Every decision records the policy applied, the data category detected, the triggering content, the action taken and the model version, so it can be replayed after the fact; deterministic rules run alongside the semantic layer for the obligations you must never miss. Regulators ask whether a control is documented, consistently applied and auditable, not whether it is deterministic.
We hold health data, banking data and insurance data under one roof. Can policies differ by business line?
Yes, and they should. Policies are scoped per group, business line or team, so Art. 35 VAG, Art. 84 KVG and the rules for health data can be enforced differently where they apply, rather than flattening everything to the strictest common denominator and blocking work that is perfectly legitimate.
Protect your employees from Art. 35 VAG exposure.
A pilot phase, run by us: an insurance policy starter pack plus a report on data leaks, shadow AI, usage and costs. Anonymize mode keeps customer and health data in the company.

