Skip to main content
    Claimory
    Security

    The security model that protects every shop on Claimory

    Postgres row-level security on every workspace table, two-factor sign-in, a claim audit trail, a security event log, rate limiting and links that expire.

    No credit card. Works with CCC ONE and Mitchell.

    Browse every category

    Database, sign-in, audit, and link security

    Security in Claimory starts at the database. Every table that holds shop data carries Postgres row-level security, so the database checks each query against the signed-in user's workspace. Sign-in adds authenticator-app two-factor on every plan, public forms and API keys are rate limited, and a claim audit trail plus a separate security event log record who changed what.

    Row-level security on every workspace table

    Every Claimory table that holds shop data has Postgres row-level security turned on. The database checks each query against the signed-in user's workspace, a second layer behind the app's own permission checks.

    Two-factor sign-in on every plan

    Claimory two-factor authentication works with an authenticator app. Turn it on from Account settings, and sign-in asks for a one-time code after the password.

    Claim audit trail

    Claimory records each claim's creation, every claim status change with the old and new status, and each claim archive, with who did it and when.

    Security event log

    A separate Claimory security log records role assignments and removals, claim archives and deletions, data deletion requests, API key changes, and failed authentication on protected requests, kept for 90 days.

    Rate limiting and bot checks

    Claimory rate limits trial and invitation sign-ups, contact and demo forms, shared file links, signing links and API keys, and its public sign-up and contact forms add a bot check before they submit.

    Encrypted mailbox tokens and platform keys

    Claimory stores connected Gmail and Outlook tokens encrypted at the column level, and platform secrets are encrypted with a key held in the database vault.

    Links that expire

    A Claimory customer portal link carries an expiry date, and a shared claim file link expires after 24 hours, 7 days or 30 days, whichever the shop picks when it creates the link.

    API keys shown once and revocable

    Claimory read-only API keys on Professional and up are shown once at creation, can be revoked from the Account page, and are rate limited per key. Creating or revoking a key writes to the security log.

    Activity on claims and cash jobs

    Each Claimory claim and cash job carries an activity history that shows who did what and when, useful for routine handoff and for a dispute with a carrier or customer.

    Team access by invitation

    A person joins a shop's Claimory workspace through an invitation from that shop, at the role the invitation sets, so nobody lands in a shop's data by signing up on their own.

    How shops use this in practice

    A new estimator joins the shop through an invitation at the estimator role and sees what that role permits. The owner turns on two-factor sign-in from Account settings. When a claim's status changes, the claim audit trail records the old status, the new one, who changed it and when. A portal link sent to a customer stops working at its expiry date, and a claim file shared with an adjuster expires on the schedule the shop picked.

    Common questions

    See security in your own shop

    14-day free trial, no credit card. Keep your CCC ONE or Mitchell estimator. You can be tracking your first supplement within minutes of signup.

    No credit card. Works with CCC ONE and Mitchell.

    See pricing
    Backed by real code in the Claimory product