Layerup
Layerup, an intelligent tool focused on improving AI efficiency.
Tags:AI improves efficiencyWhat is Layerup?
Layerup is an enterprise-grade AI agent operating system designed for insurance and financial services companies; it is used to handle processes such as claims processing, underwriting, fraud investigation, compliance, lending, debt collection, and customer service, from the point when data is entered until the results are recorded in the system. It emphasizes the use of agents within existing business systems, rather than requiring employees to switch to new chat windows.
At present, Layerup is not a general-purpose chatbot intended for individual users, nor is it an insurance Copilot that merely provides suggestions. It is designed for corporate consulting, workflow development, system integration, and phased deployment, and it is suitable for organizations that have defined processes, data governance requirements, and compliance needs.
Change in product positioning
In its early stages, Layerup offered security measures for sensitive data as well as Guardrails functionality tailored for LLM-based applications; it was also presented as a platform to improve the efficiency of insurance brokers. The current version of this product focuses on long-term AI agents used in the insurance and financial services sectors, and it should no longer be described as an older version of a general AI security SDK or as a simple broker assistant.
| Phase | Main positioning | How should it be understood at present? |
|---|---|---|
| Early Layerup Security | LLM security, prompt injection protection, and sensitive data handling | Historical products and older SDKs do not represent the current main products. |
| Insurance broker efficiency stage | Automatically handle repetitive tasks in brokerage operations | The current scope of capabilities has been expanded to include institutional-level operations. |
| Current Layerup | A sovereign-level agency operating system for insurance and financial services | Centered on long-cycle workflows, system rollback, and governance. |
Core product philosophy
Layerup defines an agent as a long-duration execution unit capable of handling the same case for hours or days. The agent maintains the status of the case, waits for any missing materials to arrive before continuing its work, and proceeds to manual approval or is placed in an exception queue at key stages.
- The agent is responsible for the entire workflow, rather than just answering a single question.
- The work takes place within existing systems for claims processing, underwriting, policies, banking, and services.
- For important decisions, a threshold for manual approval can be set.
- An audit record is maintained for each inference, invocation, and system write-back.
- Low confidence, rule conflicts, and exceptions are automatically forwarded for manual processing.
- Companies can roll out each workflow one by one, and then expand to departments and business units.
Main functions
- Multiple specialized agents are arranged to handle data reception, reasoning, execution, approval, and feedback.
- Understand insurance coverage, underwriting preferences, fraud, recovery, loans, and compliance rules.
- Read documents, emails, data warehouses, and core business systems.
- Write the processing results back to the claims, policy, loan, CRM, and service systems.
- Configure role permissions, approval thresholds, risk levels, and shutdown switches.
- Record the agent’s identity, input evidence, the decision-making process, and subsequent actions.
- Track metrics such as cycle time, throughput, losses, and SLAs through the operation dashboard.
- It supports model switching, proprietary models, open models, and custom training after model creation.
Automated claims processing
The claims processing agent can take care of everything starting from the initial report: verifying the coverage under the insurance policy, determining the severity of the situation, identifying signs of fraud or attempts to obtain unjust benefits, organizing relevant documents, providing necessary support, and handing over the case to the adjuster. It also continues to accept subsequent estimates, invoices, as well as medical or repair-related documents, and updates the status of the case accordingly.
| Claims settlement phase | Tasks that an agent can perform | Manually controlled points |
|---|---|---|
| First report of the incident | Receive reports of incidents, determine the extent of losses, and collect information on the parties involved. | High-risk or suspicious accounts routed to manual handling. |
| Responsibility verification | Match policy, limits, exclusions, and validity status | The determination of significant responsibilities is made by the authorized personnel. |
| Shunting and severity | Organize the loss signals and place them in the corresponding queues. | Upgrading of high-value or complex cases |
| Fraud and Recovery | Identify contradictions, duplicate relationships, and traceable clues. | SIU or the recovery officers examine the evidence package |
| The file is ready. | Extract documents, summarize facts, and prepare materials for decision-making. | The adjuster checks the completeness and key conclusions. |
| Write back | Update the results in the core claims processing system. | Set approvals based on amount, risk, and business line. |
Underwriting and handling of insurance application submissions
The underwriting agent receives the application documents submitted through brokerage channels or other means, extracts the relevant data, assesses the risks, checks the underwriting preferences and eligibility, and prepares quotes as well as referral materials. Applications that meet the requirements can be processed directly, while those with complex risks or risks that fall outside the designated scope are forwarded to the underwriters.
- Receive insurance application forms via email, the portal, and the system.
- Identify and categorize forms, attachments, and supplementary materials.
- Extract information on the insured person, the subject of coverage, loss records, and insurance needs.
- Filter qualifications and preferences in accordance with the institution’s own underwriting guidelines.
- Prepare rate input, quotation materials, and advanced referral packages.
- Track down the missing information and submit a request for supplementation through the brokerage channels.
- Proceed with issuing the invoice or have the system update it once approved by the underwriter.
Fraud and SIU workflows
A fraud detection agent not only assigns a risk score at the time of a report, but also compares statements, photos, invoices, medical records, repair details, and timelines throughout the course of the case. It can establish relationships between different entities involved in the case, create evidence-based investigation packages, and feed the results of those investigations back into the detection rules.
| Ability | Processing content | Final delivery |
|---|---|---|
| Continuous signal monitoring | Reporting incidents, documents, and subsequent events | Risk signals sorted by severity |
| Consistency check | Statements, documents, photos, and timeline | Contradictions and explanatory materials |
| Cross-case correlation | Employees, vehicles, addresses, suppliers, and accounts | Entity networks and repetitive patterns |
| Organizing evidence | Key fields, attachments, and event order | Referral packages available for investigators |
| Result feedback | Conclusions regarding cases that were established, not established, or could not be determined | Detection accuracy and rule calibration data |
Quality assurance and comprehensive review
QA agents are used to verify that claims documents, damage assessments, payments, underwriting decisions, pricing, and referrals comply with the organization’s own guidelines. Unlike manual sampling, this approach allows for the review of all documents, with any defects, corrections, and review processes being recorded back in the business system.
- Check whether there is a complete basis for the insurance coverage and the determination of liability.
- Verify the accuracy of loss assessment items, reserves, and payments.
- Omitted recoveries, residual values, or abnormal expenses were detected.
- Check for consistency in underwriting preferences, eligibility, and pricing.
- Provide a score, reasons, and evidence location for each defect.
- Generate correction and guidance content specific to a particular file.
- Track the corrective actions until another inspection confirms that they have been resolved.
Compliance, KYC, and AML
Financial compliance agents can carry out customer identity verification, collection of information on beneficial owners, screening for sanctions and politically exposed persons, routing of transaction alerts, as well as preparing investigation materials and reports on suspicious activities. They can also handle complaints, conduct periodic KYC updates, and organize audit evidence.
| Compliance process | Agency work | Human responsibilities that must be preserved |
|---|---|---|
| KYC and account opening | Document verification, data collection, and preparation for risk assessment | Approve account opening and handle exceptions |
| AML and Sanctions | Alarm consolidation, context collection, and false alarm analysis | Confirm actual hit and handling. |
| Investigation and Reporting | Activity summary, evidence compilation, and draft report narrative | Compliance officers review and submit |
| Complaint handling | Classification, account background, and draft responses | Confirm the regulatory approach and the final response. |
| Periodic review | Collect updated information and identify discrepancies. | Determine the risk level and subsequent actions. |
| Audit preparation | Generate operation records and evidence packages | The governance team verifies integrity. |
Customer service and omnichannel interaction
The customer service agent supports voice, chat, email, SMS, and portal sessions; they can carry out identity verification, understand the details of policies, explain bills, handle policy changes, and process certificate requests. Its goal is to move the conversation forward toward a practical solution within the core system, rather than simply creating a task to be dealt with later.
- Maintain the context of requests to retain the same customer across channels.
- Perform identity and permission verification before accessing the policy or account.
- Explain the bill and check whether the payment has been recorded correctly.
- Collect information on addresses, vehicles, drivers, or any changes in risk factors.
- Prepare insurance certificates, approval documents, or revised quotes.
- Seamless transition to claims processing or the human service queue as needed.
- Log sessions, actions, confirmations, and system writes.
Financial services workflow
Layerup’s current scope includes not only insurance but also consumer loans, bank cards and payment services, deposit banking, as well as housing loans. The typical processes involved are loan applications and related services, debt collection, handling of disputes and rejections, payment processing, account opening, KYC procedures, and loss mitigation.
| Business line | Representative process | Key indicators |
|---|---|---|
| Consumer loans | Applications, services, collection, and recovery | Treatment rate, recovery rate, and collection cost |
| Bank cards and payment methods | Disputes, chargebacks, fraud, and cardholder services | Processing cycle, losses, and SLA |
| Deposits and banks | Account opening, KYC, account services, and error handling | Account opening time, alert clearance, and compliance deadlines |
| Housing loans | Applications, services, breaches of contract, and loss mitigation | Processing cycle, material integrity, and recovery results |
| Insurance | Claims processing, underwriting, fraud, services, and QA | Cycle time, leakage, recovery, and operating costs |
System integration and write-back
Layerup emphasizes that it does not replace an enterprise’s existing systems; instead, it provides access to claims processing, policies, underwriting services, banking functions, loans, documents, email, and supplier portals through connectors and custom integrations. Write operations carried out by agents go through type-specific checks, permission verifications, and policy assessments, before being submitted in accordance with approval requirements.
- Connects cloud SaaS, data warehouses, and document storage.
- Access to enterprise internal APIs, portals, and business applications.
- Connects local databases, file systems, and legacy core systems.
- Develop custom interfaces for systems that lack ready-made connectors.
- Use service accounts with the minimum required permissions and native authentication.
- Apply unified audit and policy control to all connections.
Governance and manual approval
The platform separates planning, execution, and verification, thereby preventing a single model invocation from simultaneously deciding on actions, carrying out those actions, and evaluating itself. Every tool invocation is subject to checks based on role, scope, and responsibilities; critical actions may require manual approval depending on the business area, amount involved, and level of risk.
| Governance capacity | Function | Typical use cases |
|---|---|---|
| Approval thresholds | High-risk operations require manual confirmation. | High claim payouts, denials, and regulatory reports |
| Abnormal routing | Entries with low confidence or rule conflicts are directed to the correct queue. | Missing materials, inconsistent identities, and complex responsibilities |
| Role permissions | Restrict the systems and actions to which agents and employees can have access. | Separation of duties for valuation, underwriting, SIU, and auditing |
| Audit logs | Record time, identity, input, decision, and write-back | Internal audit, regulatory inspections, and incident analysis |
| Stop button for operation | Pause a single agent, workflow, or the entire runtime. | Abnormal behavior or security incidents |
| Ongoing evaluation | Monitor for drift, regression, and business accuracy. | Model replacement and rule updates |
Model and context architecture
Layerup supports interchangeable commercial models, open models, and proprietary enterprise models, and selects the appropriate execution path through model routing. The unified context engine provides agents with regulations, industry-specific terminology, business rules, procedures, and validation logic, rather than relying solely on the general knowledge embedded in the models.
- It allows different regions or business units to use distinct models.
- It supports the use of models provided by enterprises as well as custom models that have been trained.
- Masking, data anonymization, and residency control are applied to the input data.
- Maintain entity relationships, data lineage, and semantic indexing.
- Convert standard operating procedures into executable agent procedures.
- Use rules and deterministic tools to handle the calculation of rates, amounts, and eligibility.
Deployment method
The platform offers options for deployment in Layerup-hosted clouds, private VPCs, customer-specified clouds, on-premises data centers, and sovereign regions, and it supports isolated network scenarios. Different topologies use the same proxy operating system, but there are differences regarding where the data is stored, the keys used, how models are invoked, and who is responsible for maintenance.
| Deployment mode | Operation location | Main features | Suitable for institutions |
|---|---|---|---|
| Layerup Cloud | Supplier-hosted environment | Rapid deployment with tenant isolation. | Teams that wish to quickly validate a single workflow |
| Private VPC | Customer’s private cloud network | Preserve network, key, and isolation requirements | Organizations with clear cloud security boundaries |
| Customer cloud environment | Cloud and region designated by the enterprise | Integrated with existing cloud governance and data residency mechanisms | Large financial institutions operating across different regions |
| On-Prem | Enterprise data center | It allows for running platforms locally as well as using one’s own models. | Entities that enforce strict controls on the export of data |
| Sovereign Region | Specify the sovereign region | Regions for fixing data, performing calculations, and invoking models | Governments and organizations with high demands regarding data sovereignty |
Implementation method
Layerup usually begins with a workflow that involves high levels of friction; it progresses to production through processes such as business analysis, data analysis, value assessment, agent design, and controlled pilot testing. The deployment process relies on a shadow mode, human intervention, and automated authorization at various stages with approval checks, rather than being fully automatic from day one.
- Choose a workflow that has a clear baseline and a designated business owner.
- Review the current steps, systems, files, rules, and error paths.
- Evaluate cycle time, cost, losses, throughput, and compliance value.
- Design the connection architecture, data permissions, and proxy procedures.
- Use real-world boundary cases to establish the evaluation set and acceptance criteria.
- Run it in shadow mode first; this does not affect the production results.
- Enter the manual intervention mode to configure approvals and exception routing.
- Automatic execution with approval is enabled once the agreed targets are met.
- Continuously monitor drift, failures, regressions, and business KPIs.
- Expand gradually by department, business line, and region.
Deployment services and cycles
| Phase | Typical cycle | Main delivery | Business model |
|---|---|---|---|
| Discovery Sprint | 2 to 3 weeks | Process opportunity maps, bottleneck analysis, business cases, and integration architecture | Fixed costs, milestone-based |
| Pilot Deployment | 6 to 8 weeks | A production-grade agent for workflows, along with integration capabilities, governance tools, and KPI dashboards. | Milestone fees and KPI achievement fees |
| Enterprise Rollout | 1 to 2 quarters per business line | Agent clusters across teams, regions, and business lines | Charging based on results and throughput |
| Run & Optimize | Continue ongoing | Reliability, duty monitoring, drift monitoring, model updating, and workflow expansion | Increase subscription volume and set KPI constraints |
Price and procurement methods
Layerup does not offer any fixed monthly subscription plans for individuals or small teams, nor does it provide a self-service pricing system. The costs depend on factors such as the scope of the workflow, system integration, deployment topology, transaction volume, service level, as well as data retention and governance requirements; therefore, it is necessary to schedule a demonstration so that corporate sales staff can provide a quote.
| Purchasing items | Public price | Billing logic | Suitable for users |
|---|---|---|---|
| Platform demonstration and requirement discussion | Not disclosed | It is usually used in the initial stages of a company’s sales process. | An organization that evaluates insurance or financial processes |
| Discovery and Design Phase | Custom quote | Fixed costs and milestones | Teams that need to first determine the scope of value and technology |
| Pilot deployment | Custom quote | Milestone fees plus KPI achievement fees | An organization that verifies production workflows |
| Corporate expansion | Custom quote | By results, throughput, and deployment scope | Companies that promote their offerings across different departments or business units |
| Run continuously | Custom quote | Subscribe to additional usage and set KPIs | Customers who have reached stable production levels |
Safety and compliance
Layerup lists its compliance capabilities related to SOC 2 Type II, PCI DSS, and HIPAA, and offers deployment options in cloud environments, VPCs, on-premises locations, and sovereign regions. When making a purchase, it is still necessary to request information regarding the scope of the audit reports, their current validity period, a list of subcontractors, data processing agreements, and procedures for responding to incidents.
- Confirm the products, environments, entities, and time range covered by the certification.
- Identify which data will be fed into third-party models and how to anonymize it.
- Verify the rules for data retention, storage, deletion, and backup.
- Verify single sign-on, SCIM, role permissions, and separation of duties.
- Test the approval thresholds, shutdown switches, and rollback processes.
- Check the integrity of the logs, the methods of access, and the capabilities for exporting.
- Agree on security incident notification, recovery objectives, and supplier responsibilities.
Boundaries between regulatory and operational responsibilities
AI agents can prepare documents, apply rules, and provide evidence, but they cannot shift the responsibilities related to insurance coverage, underwriting, regulatory reporting, or the ultimate legal obligations associated with client management to the software supplier. Organizations still need to have authorized employees in charge of managing rules, handling approvals, dealing with complaints, addressing model risks, and fulfilling regulatory requirements.
| High-risk areas | The agent can take on the responsibility. | Companies must retain them. |
|---|---|---|
| Determination of insurance coverage | Organize policies and facts and provide rule matching. | The authorized personnel approve and interpret the final decision. |
| Underwriting and pricing | Prepare for input of risks, qualifications, and rates | Underwriting authority, preferences, and fairness governance |
| Fraud investigation | Detect the signal and prepare the evidence package | SIU investigations, lawful evidence collection, and final disposition |
| KYC and AML | Alarm routing, document organization, and drafts | Judgment, declaration, and regulatory communication by the compliance officer |
| Customer communication | Generate explanations, notifications, and processing steps | Accuracy, accessibility, and appeal mechanisms |
| System write-back | Execute according to typed actions | Permission design, approval, and disaster recovery |
History of SDKs, APIs, and open-source status
In its early days, Layerup Security released Python and JavaScript SDKs for use in Guardrails, prompt injection detection, and sensitive data protection. The Python package was licensed under the MIT license, and its last public version dates from 2024. Old documents and packages may still be found, but they relate to the previous version of the product and cannot be used as an official way to develop applications for the current insurance AI operating system.
The current platform supports internal APIs, connectors, and custom integrations; however, there are no available API pricing options or general SDKs for public self-registration. The Layerup insurance platform is not an open-source project, and the fact that its historical SDKs were open source does not mean that the proxy runtime, industry models, or corporate product code are also available publicly.
| Project | Current status | Label correctly |
|---|---|---|
| Layerup Insurance and Finance Platform | Proprietary enterprise products | Whether it is open source is marked as no. |
| Current public API | No self-service entry point was detected. | Enterprise integration must be confirmed by the sales and implementation teams. |
| Current general-purpose SDK | Not disclosed | Do not treat the old security SDK as the current one. |
| Historic Python SDK | MIT license; the latest public version was released in 2024. | Used solely for identifying old Layerup Security. |
| Historical JavaScript SDK | Old version of security product client | It cannot be inferred that it is still supported by the current platform. |
| Internal and custom interfaces | Enterprise deployment available | Scope, version, and SLA are specified in the contract. |
Which institutions are suitable?
- Insurance companies that wish to shorten the claims processing time and improve the readiness of the documents.
- Underwriting teams are needed to automatically process a large number of insurance applications and referral documents.
- MGA’s and specialized insurance institutions that manage multiple projects or underwriting channels.
- Insurance companies that wish to expand the coverage for fraud detection and recovery.
- Financial institutions that need automation for KYC, AML, complaints, and audit-related tasks.
- Banks and lenders that handle loan services, collection, disputes, and rejections.
- Large, regulated enterprises that require deployment in a private cloud, on-premises, or in a sovereign region.
Product advantages
- It is focused on the design of insurance and financial services processes, rather than a general chat interface.
- Long-term agents can wait for materials and continue working on the same case.
- Integrated with existing core systems to reduce duplicate data entry and manual handovers.
- Manual approval, abnormal routing, and audit logging are among the core capabilities of the platform.
- It covers claims processing, underwriting, fraud detection, QA, compliance, and financial operations.
- It supports multiple models, customer-owned models, and various deployment topologies.
- It is possible to start with a pilot workflow and then expand gradually based on KPIs.
Restrictions and Precautions
- There is no fixed public price; it requires corporate procurement and custom deployment.
- Its implementation relies on high-quality data, clear rules, and core system interfaces.
- A pilot period of 6 to 8 weeks is just a typical timeframe; complex integrations may take longer.
- Business metrics and the benefits of automation cannot be guaranteed directly without considering the customer base.
- High-risk decisions still require approval and governance by authorized personnel.
- The certification statement requires that the scope, validity period, and report be verified at the time of purchase.
- The historical Guardrails SDK cannot be used as proof of the capabilities of the current insurance platform.
- It is not suitable for individual users or teams that only want to try out a general AI assistant on a quick basis.
Evaluation and procurement list
- Choose a process that has sufficient data, clear rules, and quantifiable metrics.
- Record the current cycle, labor costs, error rate, losses, and SLA baseline.
- List the systems, documents, roles, permissions, and regulatory requirements involved.
- Require the supplier to demonstrate scenarios of anomalies, low confidence levels, and approvals.
- A validation set is created using real, anonymized cases and boundary cases.
- Verify the deployment topology, model suppliers, and mechanisms for data retention and deletion.
- Clarify the costs for integration, implementation, subscription, usage, and subsequent services.
- Include accuracy, throughput, fault recovery, and manual review in the SLA.
- Delegate authority in phases, and establish shutdown mechanisms for agents and the entire runtime.
- After going live, continuously compare business KPIs with potential deviations.
Frequently Asked Questions
Is Layerup an insurance chatbot?
No. The current product focuses on continuously executing the entire workflow in the background and writing the results back to the existing system; chat or voice are merely one of the interaction methods used in customer service scenarios.
Is Layerup only suitable for insurance companies?
Insurance is the main sector, but the platform also covers consumer loans, bank cards and payment services, deposit banking, and housing loans. Its products are still intended for regulated entities, rather than the general corporate automation market.
How much is Layerup?
There is no fixed, public monthly fee or predefined package; different customized business models are used for discovery, piloting, enterprise expansion, and ongoing operation. The actual costs depend on factors such as workflow, integration, throughput, deployment, and scope of services, and these costs need to be determined through inquiries.
Can it be deployed in an enterprise’s own environment?
Yes, the product lists deployment options such as private VPCs, customer clouds, on-premises data centers, and sovereign regions. The specific models, keys, data residency rules, and operational responsibilities need to be defined in the architecture document and contract.
Is Layerup open source?
Current insurance and financial AI platforms are not open-source products. In the early days, some SDKs developed by Layerup Security were available under open licenses, but that was part of a past approach; it does not reflect the current openness of the platforms’ runtime environments and industry models.
Will AI agents automatically make the final decision regarding claims settlement or underwriting?
The platform supports automatic execution based on predefined rules and system-based data writing back; it also offers options for manual approval, abnormal case routing, and risk thresholds. The degree of automation should be determined by the organization, taking into account factors such as amount involved, risk level, regulatory requirements, and the performance of the relevant models.
Summary
Layerup is suitable for large organizations that wish to shift insurance or financial back-office tasks from manual execution to manual approval. Its key features include long-term agent management, execution within existing systems, audit trails, manual control, and multiple deployment options, rather than providing a new chat interface.
During evaluation, it is necessary to clearly distinguish between the current enterprise platform and the previous Guardrails products, and to verify metrics such as cycle time, quality, losses, and compliance through actual workflows. The focus of procurement should be on data, integration, governance, approval processes, SLAs, and total cost of ownership, rather than merely comparing model names.
Guigong Network Security Registration No. 45132202000164