Skip to main content
hero text and image bg

Security & Trust

At Duck Creek, our goal is to provide a safe and secure environment leveraging leading technology and best practices to protect your most sensitive data and help you manage your compliance requirements.

Security Trust Hero
Shared Responsibility

Our SaaS platform called Duck Creek OnDemand provides a shared model for how our services are provided. Together with Microsoft and their Azure cloud services, we partner with customers to create a secure, flexible architecture supporting security and regulatory requirements in the cloud.

Physical Security

Microsoft’s Azure Cloud services are trusted by over 95% of Fortune 500 businesses and support over 90 compliance offerings in 140+ countries, providing levels of physical security that most companies struggle to achieve. For more information about Azure Compliance, please visit the Microsoft Trust Center at https://www.microsoft.com/en-us/trust-center.

Security Operations

Duck Creek maintains a dedicated cybersecurity organization responsible for security operations, security engineering and architecture, governance, risk and compliance, and incident response. Led by Duck Creek’s Chief Information Security Officer, the team uses centralized security monitoring and response capabilities to help identify, investigate, and respond to potential security threats.

Duck Creek’s security operations capabilities provide continuous monitoring of relevant security events and are supported by defined incident response processes, escalation procedures, and specialized resources to help contain, investigate, and recover from security incidents.

Architecture

Our OnDemand services are architected to provide numerous layers of protection, including web application firewalls and secure gateways at the edge, network isolation, multi-factor privileged access management, host-based firewalls, content filtering and advanced threat prevention to name a few. For more details on how OnDemand is built with security by design, please review our OnDemand Security White Paper.

Compliance

Regulatory and industry requirements continue to evolve, requiring organizations to address privacy, security, operational resilience, and data integrity obligations. These requirements vary by jurisdiction, industry, customer role, and the services and data involved. Duck Creek maintains a security, privacy, and resilience program designed to support the secure and reliable delivery of its SaaS offerings and to help customers meet their applicable compliance obligations.

Duck Creek OnDemand maintains an ISO 27001-certified information security management system and undergoes annual independent SOC 1 Type II and SOC 2 Type II examinations. Our program also includes annual risk assessments and internal audit activities, as well as business continuity and disaster recovery capabilities that are regularly tested. These activities provide customers with relevant assurance evidence regarding security, availability, privacy, and resilience controls.

Requirements such as GDPR, APRA operational-resilience requirements, and PCI DSS apply based on each customer’s role, regulatory environment, services, and use case. Duck Creek’s controls and supporting assurance evidence are designed to help customers meet their applicable obligations. PCI DSS requirements apply specifically where customers use Duck Creek Embedded Payments; other Duck Creek OnDemand offerings may be outside the PCI DSS cardholder-data environment and scope.

Resources
Learn More

If you are an existing Duck Creek customer or partner, please visit the Solution Center to download these documents. Otherwise, please contact information.security@duckcreek.com to request a copy.

OnDemand Security White Paper
Learn more
ISO 27001 Certification
Learn more
SOC 1 Type II Report
Learn more
SOC 2 Type II Report
Learn More
PCI-DSS SAQ-D SP
Learn more
Duck Creek DORA Whitepaper
Learn more

How can Duck Creek Help You?

Modernize your operations, unlock AI-powered insights, and deliver better outcomes—at your pace.

Select your locations and language
Select Your Language
Locations
Boston, Massachusetts (HQ)
100 Summer St 8th Floor Suite #801
Boston, MA 02110
(833) 798 7789
Sydney, Australia
360 Kent St
NSW 2000
+61 1800 430 929