PROOF OF CONCEPT · FOR W DENIS REVIEW ONLY

Confidential demonstration environment. Fictional broker branding and synthetic data. Not for commercial use.

Security & data isolation

What this demo is today, and what a production build would have to prove

This page deliberately separates the current proof of concept from the target production design. Nothing in the target column is implemented yet, and none of it should be relied on until it is built and independently validated.

This proof of concept uses fictional broker branding and entirely synthetic organisations, contacts, signals, scores and records. It does not represent a live W Denis system and no W Denis customer or prospect data is used.

Proof of conceptFictional broker brandingNo real client dataTarget controls not yet built

Column A

Current demo state

Accurate today
  • Synthetic data only

    Every organisation, contact, score and metric in this demo is invented for demonstration.

  • Browser session storage

    Anything you create during a walkthrough is held in your own browser session. There is no live customer or policy business database; reviewer feedback persistence is the only stored data.

  • Fictional broker identity

    The operating broker shown throughout is Westbridge Commercial Insurance, a brokerage invented for this demonstration.

  • No live customer data

    No W Denis client, prospect or policy information has been used or imported.

  • No live integrations

    No CRM, insurer, rating, enrichment or email integration is connected. Nothing is sent anywhere.

  • No production hosting claim

    This is a proof of concept published for W Denis review only. It is not a production service and carries no production readiness claim.

  • No regulated function

    No quoting, rating, underwriting or advice logic exists. Scores are illustrative conversation-priority values.

Column B

Target production design

Proposed · not implemented

Each item below is a proposed target control. Every one remains proposed until it is implemented, documented and independently validated.

  • Dedicated tenant & data isolation

    A W Denis tenant with logically separated data and per-tenant access boundaries enforced at the data layer.

    Target
  • Optional dedicated deployment

    Isolated application and database instances rather than shared multi-tenant infrastructure.

    Target
  • Optional customer-controlled environment

    Deployment into infrastructure W Denis owns and administers, where required by their IT function.

    Target
  • Encryption in transit and at rest

    TLS for all traffic and encryption of stored data and backups.

    Target
  • MFA, SSO and RBAC

    Enforced multi-factor authentication, optional single sign-on, and role-based permissions per broker function.

    Target
  • Least privilege

    Scoped service accounts, no shared credentials, and no standing administrative access to customer data.

    Target
  • Audit logging

    Immutable records of record access, changes, approvals, exports and administrative actions.

    Target
  • Backups & recovery

    Scheduled backups with defined RPO/RTO targets and restore testing.

    Target
  • Retention & deletion

    Configurable retention periods with documented, verifiable deletion on request.

    Target
  • Data export & exit

    Full structured export of customer data on demand and at contract end, with no lock-in.

    Target
  • Support access controls

    Support access only with approval, time-boxed, logged, and revocable by W Denis.

    Target
  • Subprocessor register

    A maintained list of any third parties involved in hosting or processing, with change notification.

    Target
  • AI / data boundary

    Explicit rules on what data may reach any AI service, with the default being no customer data leaves the tenant unless a specific integration is approved and architected.

    Target
  • Incident response

    Documented detection, containment, notification timelines and post-incident review.

    Target
  • Security testing

    Independent penetration testing and dependency/vulnerability scanning on a defined cycle.

    Target
  • UK/EU data residency options

    Region-pinned hosting and backups where required by policy or contract.

    Target

Independent validation

Go-live gate: evidence, not trust

No real W Denis or client data should be placed in this system until their IT and compliance functions have reviewed the architecture, agreed the required controls, and had isolation and security validated independently.

Complete

Concept demonstration

This synthetic proof of concept, reviewable now.

Outstanding

Architecture to agree

Target design to be reviewed with W Denis IT and compliance.

Not started

Security controls to implement

Controls on this page are proposed, not built.

Required

Independent validation

Isolation and controls evidenced by testing, not assurance.

Required

Pilot approval

Written approval before any real data is used.

JDNetworks' position for a pilot: W Denis IT/compliance define the control requirements; JDNetworks evidences each one; isolation and access controls are verified by independent testing and documented evidence rather than assurance. A written pilot approval precedes any use of real data, and the scope of that first pilot should be deliberately narrow.

Deployment options

Three illustrative target deployment models

Indicative models for discussion only, subject to technical and compliance validation. Costs, timelines and feasibility are not yet confirmed.

WRK Cloud

Shared managed platform with per-tenant logical isolation.

  • Fastest to stand up
  • JDNetworks manages hosting, patching and backups
  • Logical tenant separation
  • Region selection where supported

Lowest operational burden on W Denis IT.

Illustrative target model

WRK Dedicated

Dedicated application and database instances for W Denis only.

  • No shared database with other tenants
  • Dedicated credentials and keys
  • Independent backup and restore lifecycle
  • Change windows agreed with W Denis

Middle ground on isolation and effort.

Illustrative target model

WRK Private / customer-controlled

Deployed into infrastructure W Denis owns and administers.

  • W Denis holds the infrastructure and identity boundary
  • Support access requested, time-boxed and logged
  • Data never leaves the customer estate by default
  • Requires W Denis platform capacity

Highest control; highest joint implementation effort.

Illustrative target model

All models rely on third-party infrastructure (for example a cloud hosting provider), so we will not claim there are no third parties involved. Any such provider would be listed in a subprocessor register. Customer data would not be passed to an external service — including any AI service — unless that specific integration were explicitly requested, approved and architected with W Denis.

Next

Walk the proposition end to end, then bring IT into the architecture conversation

Demonstration dataSynthetic data only

This is a concept demonstration built by JDNetworks for the WRK ecosystem. All organisations, figures, scores and performance metrics shown are synthetic and illustrative. Nothing here constitutes insurance advice, a recommendation, a statement of policy suitability or confirmation that any cover exists. A qualified, appropriately authorised broker should assess actual insurance needs.