Trust Center
Confidential information is the foundation of investigative work. This is the central place to understand how Direct Insight Services safeguards the reports, evidence, and sensitive data our clients entrust to us โ in plain language, not IT jargon.
Our commitment
Our clients โ insurance carriers, third-party administrators, self-insured employers, law firms, corporations, and government agencies โ routinely entrust us with highly confidential information. We treat every file, image, and video with the same discretion and care we would expect for our own most sensitive matters, at every stage from intake to secure disposal.
The essentials
Reports, photographs, surveillance video, and investigative evidence are exchanged over encrypted, access-controlled channels โ protected in transit and at rest. Sensitive materials are never sent as plain, unprotected email attachments.
Case information is available only to the people who need it for a specific engagement, on a least-privilege, need-to-know basis. Access is granted deliberately and reviewed, not left open by default.
Access to client materials is protected by multi-factor authentication and secure sign-in procedures, reducing the risk of unauthorized access even if a password is compromised.
Files are stored and managed on independently audited, enterprise-grade cloud infrastructure with encryption, redundancy, and controlled retention โ not on unmanaged local devices.
In detail
A closer look at how confidential client information is handled throughout an engagement.
We exchange sensitive materials with clients through ShareFile, a secure, independently audited enterprise file-sharing platform. ShareFile provides encryption in transit and at rest, granular access permissions, and detailed activity logging. Using an established, audited platform โ rather than a homegrown system โ means client data benefits from enterprise-grade security controls and continuous third-party oversight.
Every case is handled on a strict need-to-know basis. Investigative files โ including surveillance footage, photographs, statements, and reports โ are accessed only by assigned personnel for legitimate case purposes, tracked throughout the engagement, and retained or securely disposed of in line with client requirements and applicable law.
We apply least-privilege access controls so that individuals can reach only the information required for their role on a given matter. Access to client portals and case systems is protected by multi-factor authentication and secure access procedures, and permissions are removed promptly when they are no longer needed.
Client information is stored on encrypted, enterprise-grade cloud infrastructure with backup and redundancy. We retain records only as long as necessary to serve the engagement and meet legal obligations, and we securely dispose of information when it is no longer required.
We collect and use information only for legitimate investigative purposes, in accordance with applicable law and our contractual obligations. We do not sell client or subject information. Our team operates under clear confidentiality expectations, and we are glad to execute confidentiality or non-disclosure agreements where clients require them.
We understand that some clients ask whether their vendors meet, or are working toward, formal security frameworks such as SOC 2. Our practices are designed around the same core principles those frameworks emphasize โ security, confidentiality, and controlled access. We continue to strengthen and formalize our program over time, and we're happy to discuss our current posture and roadmap directly with your security team.
Secure client portal
Existing clients use our secure ShareFile portal to submit new assignments, share confidential documents, and receive completed reports, photographs, and video. Everything moves through an encrypted, access-controlled channel with multi-factor authentication โ not ordinary email.
New client?
If you'd like secure portal access to begin working with us, contact your Direct Insight Services representative or reach out through our contact page. We'll set up a permission-controlled account for your team.
Request portal access โSecurity & compliance contact
We welcome questions about how we protect client information, and we're experienced in completing vendor security assessments and questionnaires. Reach our security and compliance contact directly:
A concise, one-page summary of our information-security practices โ formatted to attach to a vendor-approval file or security questionnaire.
View / print security overview โLooking for a signed NDA, certificate of insurance, or a completed questionnaire in your format? Ask our security contact and we'll turn it around promptly.