Independent audit underway. The controls are already in place and enforced — the report is catching up.
AES-256 at rest, TLS 1.3 in transit — on every claim, every photo, every letter. No exceptions.
Export the full claim file anytime — CSV or PDF. Month to month, no lock-in. Leave with everything.
Control who sees what across your firm, down to the claim. Client logins see their claim and nothing else.
How Brain treats your data.
The AI is the most scrutinized part of claimOS — so it runs under the strictest rules in the product.
The full story is on the Claim Brain page.
What Brain learns from your firm stays your firm's. Full stop.
You decide whether Brain learns from how you work — and you can turn it off anytime.
You set the autonomy level, from suggest-only up. Nothing leaves the office without your sign-off.
Figures link to the document they came from — auditable by you, your client, or opposing counsel.
Security questions, answered.
Where does my data live?
US data centers, encrypted at rest with AES-256 and in transit with TLS 1.3. Built and supported in the United States.
Who can see my claims?
Your firm, under roles you control — per person, per claim. Client logins are viewer-scoped: policyholders see their own claim and nothing else.
Do the AI providers see my data?
Brain runs on leading commercial models under enterprise agreements that prohibit training on your data. Your claims never train anyone else's Brain — including theirs.
What happens if I leave?
Export everything — CSV or PDF, the whole file — then we delete on request. Month to month; your data is never the hostage.
Think you’ve found a vulnerability? Email security@claimOS.net — we read every report.
Have a question we didn’t answer?
Security reviews, DPAs, questionnaires from carriers or counsel — send them over.