Trust & delivery
The detail your
team needs to see.
A publisher partnership has to work for product, commercial, engineering, legal and procurement. Here’s how we approach those conversations.
Security belongs
in the delivery plan.
Our approach includes the controls and responsibilities needed for the agreed deployment. Detailed implementation evidence is reviewed as part of partner due diligence.
- Access & environments
- Review role-based access, credential management, environment separation and who can access partner or customer information.
- Infrastructure & resilience
- Azure delivery experience informs architecture planning, monitoring, recovery and availability requirements. Explore the infrastructure
- Data handling
- Agree what is collected, why it is needed, who is responsible and how it is shared, retained and removed.
- Operational ownership
- Set named contacts, incident escalation, change control, maintenance responsibilities and the support arrangement.
A useful start
to due diligence.
Bring your procurement questionnaire. We’ll work through the requirements and identify the evidence and agreements relevant to the proposed launch.
- Architecture, hosting and data flows
- Data roles and processing agreements
- Supplier and subprocessor information
- Security controls and testing scope
- Availability, recovery and incident responsibilities
- Support, escalation and change management
- Commercial attribution and reconciliation
- Customer disclosures and launch approvals
Clear about
the operating model.
The business website describes the partnership proposition. It does not provide live insurance quotations or sell policies.
Before a customer launch
Confirm the relevant entities, insurer arrangements, regulatory permissions, disclosures and approval requirements for the specific journey.
For the initial journey
Customers complete details, explore returned quotes and continue to an insurer. The insurer completes the purchase; later extensions require their own arrangements.
Regulatory framework
Clear about who
provides the service.
Yeti Engines Ltd is an Appointed Representative of Innovative Risk Labs Limited, which is authorised and regulated by the Financial Conduct Authority (FRN 609155).
Yeti Engines carries on the regulated activities covered by its appointment under the responsibility of Innovative Risk Labs Limited. Partner activities, customer disclosures and required approvals are agreed for each distribution journey.
The appointed representative relationship does not automatically extend to a publisher’s own activities. The partnership is structured around what each party will do.
A few useful answers.
Can we use our own procurement process?
Yes. Share your requirements and we’ll work through the proposed deployment, controls, responsibilities and available evidence with the relevant people on your team.
What service level can you offer?
Support and service levels are agreed for the deployment and recorded in the relevant agreement. We do not present an illustrative target as an existing contractual guarantee.
Is Cyber Essentials complete?
The stated status is assessment scheduled. We do not describe that as certification.
How do we report a security concern?
Email security@yetiengines.com with a description and enough information to investigate. Please avoid including unnecessary personal information or credentials.
Bring the questions
your team will ask.
We’ll bring the right people into the conversation.