How your documents are handled
Benefits Studio is built on a design philosophy that shapes every security decision underneath the product: the information published on a Benefits Studio portal is information the employer already intends to share with everyone who works there. That's a genuinely different security posture from platforms that store claims history, medical records, or an employee's personal account data, and it's worth being explicit about why.
The information itself is public by design
A published benefits portal displays what an employer already communicates openly, plan summaries, carrier contact information, benefit categories, open enrollment dates. Summary of Benefits and Coverage documents are federally required to be disclosed to every eligible employee. Carrier phone numbers and websites are on the back of every insurance card. Deductibles and copays are what an employee sees at every doctor visit.
Benefits Studio is a communication tool. Companies like Walmart and Starbucks publish their entire benefits site openly, they want candidates and employees to see what's offered. Every employer should be able to do the same.
Because the information on a published portal is meant to be seen, Benefits Studio does not process, store, or transmit sensitive, confidential, or proprietary employee data. There are no claims. No medical records. No personal account balances. No employee identifiers of any kind.
That said, some employers prefer their site not be openly browsable, and an optional site password is available on every plan. It's a privacy signal, not a security control: one shared password keeps the site off search engines and away from strangers, while employees still never create accounts and no employee identity is introduced. The posture above holds unchanged either way.
This shapes everything below.
Storage
Plan documents live in private, encrypted storage while an admin is building a portal. Nothing is publicly accessible until the admin chooses to publish it. When a document is served, it's served through a signed URL that expires shortly after use, forwarding it later won't work. This is the design, not a feature we might add later.
Access
Drafts are private to the admin building the portal. Extracted data, review notes, and unpublished work are visible only to that admin, not to other brokers on the platform, not to employees, not to us in the ordinary course of business.
When the portal is published, employees see only the data the admin confirmed. Anything flagged, rejected, or left in draft stays in the admin dashboard and never reaches the public site.
Benny
Benny is the assistant employees can ask questions to. Two things worth being direct about.
Benny only reads the documents uploaded to that specific portal. Not general internet knowledge, not other companies' plan documents, not last year's version of your own. When an employee at Company A asks Benny a question, Benny is looking at Company A's documents and nothing else. Cross-portal isolation is enforced at the database layer, not just the interface.
Benny does not train on your documents. Our AI provider processes the relevant sections of your plan documents at the moment a question is asked, generates an answer, and moves on. Your documents are not used to improve any AI model, not shared with other customers, and not retained beyond what's required to serve the request.
Employees
Benefits Studio does not collect personal information from employees. There are no employee accounts. No sign-in. No email addresses collected. No tracking pixels. This is a real privacy improvement over the industry default of putting benefits behind a login where every employee's usage patterns get logged, and it's also just a better experience: nothing to forget, nothing to remember, nothing to lose access to when someone changes departments.
From an employee visit we record anonymous counts — how many times a page was viewed, how many questions Benny answered — and we store the questions typed to Benny with a random session ID so the benefits team can see what topics come up. None of it is tied to an individual: no accounts, no email, no tracking pixels, and no employee is ever identifiable.
About compliance frameworks
Frameworks like SOC 2 and HIPAA exist to protect non-public data, medical records, claims history, personal account information, from unauthorized access. Benefits Studio doesn't handle that kind of data by design. The information published on a portal is information the employer already shares openly with every eligible employee, so the frameworks built to certify the handling of confidential data don't map to what this product does.
That said, we've built to the practices those frameworks describe, encryption in transit and at rest, least-privilege access, tenant isolation at the data layer, no logging of employee personal information, because they're good practices regardless of whether a certificate is on the wall.
If your organization has specific security requirements or wants to walk through how any of this works in more detail, we'd rather have that conversation up front than surprise you later. Use the contact form if you have any questions.