You're about to put your vendor list, their agents' contact details, and their insurance documents into someone else's software. Here is precisely what happens to all of it.
Certificates you or your vendors' agents upload are stored on servers we operate ourselves, in the United States. They are not placed in a public cloud storage bucket, and they are not shared with other CertWatch customers. Each customer's records are separated by account, and every request is checked against the account it belongs to before anything is returned.
When a certificate arrives, we use Google's Gemini to read the document and pull out the coverage lines, limits, dates and certificate holder. This is how the app can tell you a limit is short instead of just filing a PDF. That means the contents of an uploaded certificate are sent to Google for processing.
We think you should know that plainly rather than find it in a sub-processor list. If that is a problem for your business, tell us before you sign up — certificates can be entered by hand instead, and nothing is sent anywhere.
Payments are handled by Stripe. Card numbers are entered directly with Stripe and never pass through or rest on our systems — we store only the plan you're on and whether it is paid. We could not show you your own card number if you asked.
Your vendors' insurance agents never create a login. Each certificate carries its own unguessable one-time link, and that link only ever reaches the single certificate it belongs to. An agent who receives a link for one vendor cannot see your other vendors, your requirements, or anything else about your account.
This is deliberate. Asking a busy agency to register for an account is the fastest way to never receive the certificate.
Reminders and correction requests are sent through Brevo, and they go out under your business name with replies routed back to you — the agent sees the business asking for the certificate, not a piece of software. We do not use your vendors' or their agents' addresses for our own marketing, and we do not add them to any list.
You can remove a vendor and its documents from your account at any time. If you want the whole account and everything in it deleted, email contact@signatureinsuranceky.com and we will do it and confirm when it's done. Bear in mind a certificate history is often the thing you most want during an audit or a claim, so consider exporting before you delete.
If you believe you've found a security issue, email contact@signatureinsuranceky.com or call 859-407-4888. A real person will read it.
Last updated 20 August 2026.