QuickAIProposal is a document-processing tool for licensed insurance agents, operated by beaconAI. This page describes how it handles data, who processes it, and what a corporate network needs to allow.
Last updated August 2026
Hostnames to allow (TCP/443, TLS 1.2+):
www.quickaiproposal.app quickaiproposal.app
There is no stable inbound IP to allowlist. The application is served from Vercel’s anycast edge network, which does not assign a fixed public ingress address, so this must be allowed by fully-qualified domain name in the proxy or secure web gateway rather than by IP.
If this domain is being isolated or blocked on your network, it is a URL categorisation matter rather than a content or malware finding — the site is a standard business SaaS application. We are happy to answer a security questionnaire; contact details are at the foot of this page.
Agents upload insurance quote documents and, optionally, a prospective customer’s current carrier declaration pages. These documents can contain nonpublic personal information (NPI) about the agent’s customer — names, addresses, vehicle details, coverage limits and premiums. The product extracts the figures needed to build a comparison proposal.
Agents are responsible for handling their customers’ NPI in line with their own obligations, including the Gramm-Leach-Bliley Act and applicable state insurance data-security law. This page is intended to support that diligence, not replace it.
| Data | Where | Retention |
|---|---|---|
| Agent account — name, email, agency, contact details set in the profile | Supabase (PostgreSQL, US) | Life of the account |
| Quote activity counters — a timestamp and quote type per proposal, containing no customer information | Vercel KV | 400 days |
| Billing — subscription status and Stripe customer reference | Supabase / Stripe | Life of the account |
| Uploaded documents and extracted customer details | Not stored | Held in memory for the request only |
Customer names, addresses and policy details are not written to our database or our counters. See the Privacy Policy for the full statement and for deletion requests.
| Provider | Purpose | Trust information |
|---|---|---|
| Vercel | Application hosting and edge delivery | security.vercel.com |
| Supabase | Authentication and PostgreSQL database | supabase.com/security |
| Anthropic | Claude API — document data extraction and copy generation | trust.anthropic.com |
| Stripe | Subscription billing and payment processing | stripe.com/docs/security |
| SmashSend | Transactional and lifecycle email | smashsend.com |
Document contents are sent to Anthropic solely to perform the extraction the agent requested. Per Anthropic’s commercial terms, inputs and outputs submitted through their API are not used to train their models by default.
Stated plainly, because a vague answer is worse than a candid one:
If your organisation requires a security questionnaire, a data-processing agreement, or evidence beyond this page, please get in touch and we will work through it.
Email dale@beaconai.ai with “Security” in the subject. We aim to acknowledge within two business days. Please give us a reasonable window to remediate before public disclosure. We will not pursue action against good-faith research that avoids privacy violations and service disruption.
beaconAI — beaconai.ai
dale@beaconai.ai