Security Architecture
This security audit evaluates the Insurance Triage Evolved platform, focusing on its frontend architecture, backend automation workflows, and data handling practices. This assessment was partially conducted using security-audit-checker.vercel.app, a specialized tool developed by Gijs Hulsebos.
1Executive Summary
The Insurance Demo platform demonstrates a "Security by Design" approach. By leveraging modern cloud infrastructure (Vercel) and robust workflow orchestration (n8n), the system minimizes common attack vectors like server misconfiguration and unauthorized API access. While the core architecture is highly resilient, one minor credential exposure was identified during the automated scan that requires immediate rotation.
2Infrastructure & Hosting Security
The decision to host on Vercel provides several out-of-the-box security advantages that are critical for an insurance-related application:
- Environment Variable Isolation: Sensitive keys (AI API keys, database credentials) are never stored in the codebase. They are managed through Vercel's encrypted dashboard, preventing accidental exposure via Git history.
- Static Analysis & CI/CD: The use of
eslint.config.mjsand TypeScript (tsconfig.json) ensures that code-level vulnerabilities are caught during the build process before reaching production. - DDoS Protection & Global Edge: Vercel provides automatic mitigation against layer 3 and 4 attacks, ensuring the claims portal remains available during traffic spikes.
3Backend & Workflow Security (n8n)
The backend logic is handled via a complex n8n workflow, which introduces several "Defense in Depth" layers:
Authentication & Perimeter Defense
- Header-Based Security: The primary entry point (Insurance Demo Webhook) is protected via headerAuth. This ensures that only authorized requests from the frontend can trigger the claims processing logic.
- Webhook Obfuscation: The workflow uses a unique, non-guessable UUID for the webhook path, significantly reducing the risk of "IDOR" or brute-force discovery.
Gatekeeper & Fraud Prevention
- AI Gatekeeper Logic: The AI Agent node includes strict "Gatekeeper Logic." It is programmed to reject nonsense inputs or unrelated data, acting as an automated first line of defense against "Prompt Injection" or fraudulent spam.
- Validation Status: The system uses a Structured Output Parser to ensure that AI-generated responses conform to a strict JSON schema, preventing downstream processing errors.
4Data Privacy & GDPR Compliance
Given the sensitivity of insurance data, the workflow incorporates dedicated privacy nodes:
- PII Vaulting: The workflow explicitly separates Personally Identifiable Information (PII) like
user_emailandpolicy_numberinto a "PII Vault" before sending data to the AI agent for analysis. - Anonymization: The
compliance_metatag indicates that data is flagged asgdpr_anonymized: trueduring the processing phase. - Human-in-the-Loop (HITL): High-risk claims (Urgency Level 3) or low-confidence AI scores trigger a manual review via the "Human Review?" logic, ensuring that sensitive decisions are not left solely to an algorithm.