Know which vendors are actually insured. Today, not at renewal.
A certificate that was good in March is worthless in September, and nobody finds out until the loss. Your contracts already say what each vendor has to carry. The work is proving, on any given day, that every one of them still does.
Who this is for: Cities, counties, school districts, special districts, transit and housing authorities, and the risk office inside them.
What is built
Each item below is generated from an inventory in which every entry names the source files that implement it. Where a capability has a boundary, the boundary is printed with it.
Automated parsing of insurance certificates and evidence documents: ACORD 23, 24, 25, 27, 28, 101 and 131, a generic ACORD path, HO-4 dec pages, and application sections, with an OCR path for non-ACORD and scanned documents.
A configurable rules engine that evaluates each policy against a client-defined ruleset and produces itemized deficiencies: additional-insured naming, endorsement attachment, minimum limits, days-until-expiration, carrier admitted status, carrier AM Best rating, MCS-90 minimum financial responsibility, required wording, and interested-party naming.
A tokenized vendor upload portal: each vendor gets its own link, uploads certificates without an account in the main application, and sees its own open deficiencies and upload history.
Boundary: Uploads are capped at ten megabytes and checked by file type. A vendor link expires after ninety days.
A certificate-holder portal where a third party can submit and verify certificates without an account in the main application.
Scheduled re-verification: policies are re-evaluated on a cadence, expiring coverage is chased automatically, documents stuck mid-pipeline are swept, and lifecycle reminders and escalations are generated without staff action.
When verification opens a new blocking deficiency the vendor is emailed automatically with what failed, grouped into one message per certificate rather than one per broken rule. A vendor that returns to compliance is emailed too, and a vendor with no contact email is surfaced on the dashboard instead of being silently skipped.
Boundary: Email is the only outbound transport in the product, so nothing routes into a chat tool, a pager or another system. Only blocking deficiencies send, and warnings surface on the dashboard instead.
One-click generation of an auditor-ready PDF packet covering an organization's compliance posture, with free-text scrubbing applied before rendering.
A multi-tenant, organization-scoped web application covering vendors, certificate holders, policies, rulesets, MVR orders, audit history, and billing settings.
Every server-side mutation writes an append-only audit row recording the actor, the action, the target, the timestamp and the caller fingerprint, with personal data scrubbed out of the recorded metadata before it is stored.
Boundary: The organization audit log is append-only by design. The hash-chained log described on the software page is a separate control over a separate table.
Sensitive personal data is encrypted at the field level before it is written to storage.
How the work happens
You define compliant, once
Coverage lines, minimum limits, required endorsements, exact wording, admitted status, an AM Best floor, and how far ahead of expiration you want to know. That set is versioned, so two years from now you can still show what was required on the day a certificate was scored.
Each vendor gets its own link
No account, no password, no reset call to your help desk. The vendor or its broker opens the link, uploads a certificate, and sees its own open deficiencies and upload history. Your staff is out of the middle.
The check repeats whether anyone remembers or not
Active policies are re-evaluated on a cadence, coverage running out is chased, and a vendor whose certificate fails a blocking rule is emailed with exactly what to fix. A vendor with no contact email surfaces on the dashboard rather than being quietly skipped.
Talk to the person who builds it
Send the scope, the question, or the solicitation itself. If you are doing market research before writing one, that is a conversation we are glad to have.
This product reads certificates and applies your rules. It is not a broker of record and it does not place your coverage.