Western SurplusCarrier audit portal Authorized access only
← Back to the portal

WESTERN SURPLUS CARRIER AUDIT PORTAL

Privacy Policy

Pilot draft · September 10, 2026. This notice describes the portal's current behavior. Western must review its retention, operational logging, and disclosure practices before external release.

This portal provides carrier-authorized, read-only access to policy and quote files. Western Surplus uses account information and activity records to manage that access, support audits, and investigate access problems.

Account information

The portal stores your name, email address, Microsoft tenant and user identifiers, whether your account is enabled, its expiration, and your carrier assignments and access dates. Your Microsoft password is entered with Microsoft, not collected by this portal.

What your activity record contains

Recorded events identify the portal user, time, action, and outcome. Depending on the action, they also include quote and carrier identifiers, folder, document or page identifiers, frame/version information, and bounded result or page counts.

The portal activity log does not contain document images, document text, Microsoft passwords, or authentication tokens. It does not record your screen or keystrokes.

Recent files and browser storage

Recent files come from your successful file-open events in the last 30 days. Up to 20 currently authorized matches are shown from your 100 most recently opened distinct files in that period. Current carrier access and AIM information are checked again before details are returned. Another auditor's history is not shown to you.

The portal uses necessary sign-in and request-protection cookies. Displayed page images may be retained temporarily in the open tab's memory to make revisits faster, with fresh access checks. The portal does not use persistent browser storage for recent files or document images, and does not include advertising or third-party analytics scripts. Signing out invalidates your portal sessions on all devices, but does not erase server-side activity records or downloaded copies.

Operational records and access

Western portal administrators can review activity records. Authorized system/database operators may also have access when administering the service. Microsoft sign-in services, the web server, and source document systems may keep separate operational and security logs, such as connection, request, timing, error, and sign-in information. Those systems' records are separate from the portal activity log described here.

Retention and questions

Activity records are append-only through the portal: its normal administrator interface cannot edit or delete them. The application currently has no automatic audit-record deletion schedule. The 30-day recent-files display is not a 30-day deletion policy. Western's approved retention schedule, backups, and any applicable retention requirements must be confirmed separately.

Contact your Western representative or portal administrator with questions about your information, access, activity records, or this notice. Any access, correction, or deletion request requires review; this notice does not promise deletion of records that must be retained.