For insurers and investors

AI-first insurance operations.

Insurance administration cheap enough to make very small policies economically viable.

TopSure runs distribution, onboarding, policy administration and claims verification for one product: accidental death cover for gig workers, starting in Indonesia. A licensed insurer issues the policy, holds reserves and carries the risk.

  • Accidental death only
  • Indonesia first
  • Carrier-replaceable
  • Every decision auditable

Prototype. TopSure is not an insurer and does not hold an OJK insurance licence. No insurer partnership is in place yet; the console uses sandbox carriers and fictional data.

The model

We run the operations. You carry the risk.

Simplicity is the cost advantage: one product, one payout trigger, fixed benefit amounts and minimal data. Nothing is built that doesn't cut acquisition, servicing, claims or fraud cost.

TopSure

Technology and distribution layer

  • Distribution inside a two-minute mobile flow
  • Onboarding: identity, beneficiary, consent records
  • Policy administration and premium collection
  • AI evidence extraction and verification for claims
  • Fraud signals and a complete evidence package per claim
  • An audit trail for every automated step
Licensed insurer

Regulated risk carrier

  • Issues the policy under its OJK licence
  • Approves the product, wording and pricing
  • Holds reserves and carries the insurance risk
  • Keeps legal claims authority (it may delegate approval of clean claims)
  • Pays claims, directly or through TopSure rails
Customer app & claims
CarrierService
Carrier A adapterCarrier B adapterCarrier C adapter

Straight-through claims

Evidence in. Verified facts out.

Target: 90–95% of clean claims need little or no manual processing once the data integrations exist. The AI reads and cross-checks evidence. It does not decide.

  1. 01Beneficiary enters phone number or TopSure ID
  2. 02Policy found
  3. 03Beneficiary verifies identity (OTP)
  4. 04Uploads documents or connects sources
  5. 05Document AI: classify, extract, check tampering and duplicates
  6. 06Independent-source verification: one fact at a time
  7. 07Deterministic rules decide the route

Per-fact confidence

Example output
  • Identity verified99%
  • Death verified99%
  • Accidental cause97%
  • Beneficiary verified99%
  • Fraud riskLOW

Not a single opaque score. Each fact lists the sources that support it, each source's weight and any source that contradicts it. Insurers and auditors can see exactly why a fact counted as verified.

Coverage rules engine

Eligibility is code, not a model.

The conditions below are rendered live from the product configuration. The insurer's wording sets them; the AI only supplies the facts.

AUTO_APPROVAL_ELIGIBLE

Every condition passes at or above 95% confidence, nothing is missing and fraud risk is LOW. The package goes to the insurer, or is approved under delegated authority if the insurer grants it.

REQUEST_MORE_EVIDENCE

A fact is unknown or below threshold, or a required document is missing. The family is told exactly what to add.

HUMAN_REVIEW

Sources conflict, a condition fails or fraud risk is MEDIUM or HIGH. A person reviews. Only the insurer can decline.

The LLM is notthe system of record.

Policies, payments and claim states live in a transactional database behind strict state machines.

The LLM is notthe payment authority.

Payouts follow an insurer decision or the insurer's written delegation, never a model output.

The LLM is notthe insurance policy.

Coverage comes from the insurer's wording, encoded as versioned configuration.

AI cost

Cheapest capable tier, every time.

A model router sends each task to the cheapest tier that can do it. The reasoning model runs only when evidence conflicts or fraud signals trigger. Personal data is redacted before any external model call.

Tiers

TierWhatUnit costPII

Unit costs are placeholder assumptions in IDR, to be replaced with contracted prices.

Routing

    Insurer integration

    Carrier A, B or C. Same app.

    Every insurer integration sits behind one interface. Adding or replacing an insurer means writing one adapter, whether its systems use an API, file exchange or a portal. The customer app, the claims engine and existing policies stay untouched.

    • Policies record which carrier issued them
    • New business can be switched to another carrier with a single default
    • Every outbound call is audited
    • Evidence packages carry tokens, not raw identity numbers

    Regulatory architecture

    Configurable terms. Auditable events.

    Built on the assumption that TopSure is a technology and distribution company working with a licensed Indonesian insurer. The interface always names the insurer that underwrites the cover.

    Configured per insurer and product

    • Insurer name
    • Policy wording
    • Product disclosure
    • Exclusions
    • Premium
    • Commission
    • Taxes
    • Waiting periods
    • Eligible ages
    • Maximum payout
    • Territorial coverage
    • Cancellation rights
    • Claims authority
    • Cause-of-death taxonomy
    • Data retention

    Recorded with an event ID, timestamp and hash

      Each event chains to the previous one by hash, so any edit or deletion is detectable. Payloads are scrubbed: no ID numbers, phone numbers, account numbers or names.

      Policy state machine

        Claim state machine

          Transitions not listed are rejected. Only insurer review can lead to a decline.

          Security and privacy

          Death records, IDs and bank details. Treated that way.

          Implemented in the prototype
          • Tokenisation vault: NIK, phone, names and accounts are replaced by tokens in services and logs
          • Audited reveal: personal data is detokenised only with an actor and a reason
          • PII redaction before any external AI call, with re-identification inside TopSure
          • Hash-chained, PII-scrubbed audit log with tamper detection
          • Strict policy and claim state machines
          • On-screen masking of ID and account numbers
          • Disclosure text hashed into each consent record
          Production infrastructure (not in the prototype)
          • Encryption in transit (TLS) and at rest with managed keys
          • Field-level encryption for sensitive columns
          • Strict role-based access; MFA for every admin and assessor
          • Session management, rate limiting and device or risk signals
          • Secure document storage with per-claim access and retention schedules
          • Write-once audit storage, with the head hash anchored with the insurer
          • Penetration testing and data protection impact assessment under Indonesia's PDP Law

          Partner with TopSure

          Underwrite the next million small policies.

          We're looking for a licensed Indonesian insurer to underwrite RideLife, and for reinsurance and investment partners.