Claims data is personal data. CFX is fully compliant with the Personal Data Protection Act (PDPA) and CIS IT Security Standards, so every claim we handle is protected end to end — from first notification through to final settlement.
Security is built into how we work, not added afterwards: hardened platforms, controlled access, and a secure development lifecycle that keeps our operations audit-ready.
We comply with the Personal Data Protection Act to safeguard personal data and privacy at every step of the claims journey — collection, processing, storage and disposal.
We follow CIS Controls to establish a strong security foundation across people, processes and technology, benchmarked against a recognised international standard.
Application security aligned with the OWASP Application Security Verification Standard.
Protection against the most critical and prevalent web application risks.
Built using the OWASP Secure Coding Practices, reviewed at every release.
Follows CIS secure software development lifecycle principles end to end.
SAST, DAST, vulnerability assessment and penetration testing best practices.