Security

How we handle your claim data.

Public adjusters work with highly sensitive material — policy documents, medical records, photos of loss, client PII. claimOS is built around that. Here's the current state of how we protect it.

Encryption

  • AES-256 encryption at rest across all customer data
  • TLS 1.3 in transit — every request to every endpoint
  • Per-workspace encryption keys managed through our hosting provider

Access & auth

  • Role-based access control on every workspace
  • SSO / SAML available for Growth and larger plans
  • Audit trail for every claim-level action (create, edit, share, export)

Compliance

  • SOC 2 Type II audit actively in progress
  • Data residency in U.S. AWS regions only
  • DPAs available on request — contact security@claimos.net

Data portability

  • Full export of claims, documents, and photos as CSV + PDF at any time
  • No vendor lock-in — your data stays yours
  • 30-day retention after cancellation, deletion on request

Have a specific security question?

We're happy to walk through our architecture, share SOC 2 progress, or sign a DPA. Email security@claimos.net and we'll respond within one business day.