How your documents are handled
Benefits Studio is built on a design philosophy that shapes every security decision underneath the product: the information published on a Benefits Studio portal is information the employer already intends to share with everyone who works there. That's a genuinely different security posture from platforms that store claims history, medical records, or an employee's personal account data, and it's worth being explicit about why.
The information itself is public by design
A published benefits portal displays what an employer already communicates openly, plan summaries, carrier contact information, benefit categories, open enrollment dates. Summary of Benefits and Coverage documents are federally required to be disclosed to every eligible employee. Carrier phone numbers and websites are on the back of every insurance card. Deductibles and copays are what an employee sees at every doctor visit.
Benefits Studio is a communication tool. Companies like Walmart and Starbucks publish their entire benefits site openly, they want candidates and employees to see what's offered. Every employer should be able to do the same.
Because the information on a published portal is meant to be seen, Benefits Studio does not process, store, or transmit sensitive, confidential, or proprietary employee data. There are no claims. No medical records. No personal account balances. No employee identifiers of any kind.
This shapes everything below.
Storage
Plan documents live in private, encrypted storage while an admin is building a portal. Nothing is publicly accessible until the admin chooses to publish it. When a document is served, it's served through a signed URL that expires shortly after use, forwarding it later won't work. This is the design, not a feature we might add later.
Access
Drafts are private to the admin building the portal. Extracted data, review notes, and unpublished work are visible only to that admin, not to other brokers on the platform, not to employees, not to us in the ordinary course of business.
When the portal is published, employees see only the data the admin confirmed. Anything flagged, rejected, or left in draft stays in the admin dashboard and never reaches the public site.
Benny
Benny is the assistant employees can ask questions to. Two things worth being direct about.
Benny only reads the documents uploaded to that specific portal. Not general internet knowledge, not other companies' plan documents, not last year's version of your own. When an employee at Company A asks Benny a question, Benny is looking at Company A's documents and nothing else. Cross-portal isolation is enforced at the database layer, not just the interface.
Benny does not train on your documents. Our AI provider processes the relevant sections of your plan documents at the moment a question is asked, generates an answer, and moves on. Your documents are not used to improve any AI model, not shared with other customers, and not retained beyond what's required to serve the request.
Employees
Benefits Studio does not collect personal information from employees. There are no employee accounts. No sign-in. No email addresses collected. No tracking pixels. This is a real privacy improvement over the industry default of putting benefits behind a login where every employee's usage patterns get logged, and it's also just a better experience: nothing to forget, nothing to remember, nothing to lose access to when someone changes departments.
The only thing we record from an employee visit is anonymous counts, how many times a page was viewed, how many questions Benny answered, so an admin can see whether the portal is being used. No individual employee is ever identifiable.
About compliance frameworks
Frameworks like SOC 2 and HIPAA exist to protect non-public data, medical records, claims history, personal account information, from unauthorized access. Benefits Studio doesn't handle that kind of data by design. The information published on a portal is information the employer already shares openly with every eligible employee, so the frameworks built to certify the handling of confidential data don't map to what this product does.
That said, we've built to the practices those frameworks describe, encryption in transit and at rest, least-privilege access, tenant isolation at the data layer, no logging of employee personal information, because they're good practices regardless of whether a certificate is on the wall.
If your organization has specific security requirements or wants to walk through how any of this works in more detail, we'd rather have that conversation up front than surprise you later. Use the contact form if you have any questions.