System of Record for Customer Data Compliance
At Droplets, we offer comprehensive solutions to ensure insurance agencies and auto dealerships are fully equipped to handle the complexities of customer data security and regulatory compliance.
Our services include the following, tailored specifically for each insurance agency and auto dealerships:
- Written Information Security Programs (WISP)
- Risk Assessment
- Policy and Procedure Development
- Annual Cybersecurity Training
- Incident Response Plans (IRP)

How it works

Comprehensive Risk Assessment
Our experts conduct thorough risk assessments to identify potential vulnerabilities in your customer data security infrastructure, ensuring that your WISP and IRP are robust, effective, and audit ready.

Expertly Crafted Security Programs
We develop detailed WISPs that outline the policies and procedures necessary to protect sensitive customer information, keeping your agency & dealership in compliance with federal and state regulations to include the FTC Safeguards Rule.

Proactive Incident Response Planning
We make your business’ required IRP part of the WISP services (bundled into one cohesive program) and provide you with a clear, actionable plan for responding to data breaches and other security incidents, minimizing potential damage and ensuring a swift recovery.
Why choose Droplets?
Professional Expertise: Our team consists of seasoned professionals with extensive experience in cyber compliance and customer data security. We stay up-to-date with the latest regulations and industry best practices to provide you with top-notch services.
Customized Solutions: We understand that every insurance agency and auto dealership is unique. Our WISP and IRP services are tailored to meet the specific needs of your business, ensuring that you receive the most effective and relevant solutions.
By partnering with us, you can rest assured that your business’ customer data security and compliance needs are in expert hands.

Regulatory agencies requiring WISPs
Auto Dealerships & Insurance Agencies
FTC Safeguards Rule
- 16 CFR §314.4 – FEDERAL TRADE COMMISSION (FTC), SAFEGUARDS RULE (All insurance agencies and auto dealerships in the US).
- NATIONAL LEVEL CUSTOMER DATA PROTECTION REGULATIONS.
Insurance Agencies that Sell Financial Products (Series 6 & 63)
SEC/FINRA Regulation S-P
- 17 CFR §248.30 – SECURITIES AND EXCHANGE COMMISSION (SEC), REGULATION S-P (Series 6 & 63).
- NATIONAL LEVEL CUSTOMER DATA PROTECTION REGULATIONS.
Insurance Products in New York
- 23 NYCRR §500 – CYBERSECURITY REQUIREMENTS FOR FINANCIAL SERVICES COMPANIES (All NY licensed agencies)
- STATE LEVEL CUSTOMER PROTECTION REGULATIONS IN NEW YORK.
Insurance products states other than NY.
- NAIC MODEL LAW 668 – INSURANCE DATA SECURITY LAW
- STATE LEVEL CUSTOMER DATA PROTECTION REGULATIONS FOR INSURANCE PRODUCTS. CURRENTLY BEING ENACTED IN STATE ACROSS THE US (2025)
Contact Us
We would love to hear from you. If you are interested in receiving a demo for PitCrew or in our compliance services, please submit our contact form. We typically respond within 24-48 hours.
