Your claim data stays yours. Here is how.
Claimory handles customer names, addresses, phone numbers, VINs, and DRP paperwork every day. This page is a straight answer to what we do with that data, where it lives, who can see it, and what our AI does and does not do with it.
No credit card. Works with CCC ONE and Mitchell.
The controls protecting your workspace
No buzzwords. Specific controls, named.
Encryption in transit
All traffic between your browser and Claimory runs over TLS 1.2+. HTTPS is enforced site-wide; HTTP requests are redirected automatically.
Encryption at rest
Claim data, photos, documents, and backups are stored encrypted at rest with AES-256 inside Supabase-managed Postgres and object storage.
Row-level security (workspace isolation)
Every single database query is scoped to your workspace by Postgres RLS policies. One shop cannot read, write, or even enumerate another shop's claims, customers, or files.
Role-based access control
Owner, Manager, Estimator, and Technician roles each get a defined permission set. The floor never sees billing. The office manager never has to ask for access.
Audit logging
Who did what, when, and on which claim. Full audit trail for every workspace action, retained for the life of the account.
Authentication
Email and password with bcrypt hashing. Session cookies scoped HTTP-only and Secure. Two-factor authentication (TOTP authenticator app) is available; enable it from Account settings.
How your data is handled
Where it lives, how long we keep it, what happens if something goes wrong, and what happens when you leave.
Where your data lives
Production data is hosted on Supabase (Postgres + object storage) in US regions. No customer data is stored on developer laptops or third-party analytics vendors.
Customer PII posture
Shops handle customer names, addresses, phone numbers, VINs, and sometimes SSNs on DRP paperwork. We treat all of it as sensitive. It is encrypted at rest, scoped by RLS, and never sent to marketing tools or ad networks.
Backups and retention
Automated daily backups via Supabase, our infrastructure provider. Deleted workspaces are purged from primary storage on cancellation; backup images roll off on the provider's standard retention window.
Incident response
Security incidents are triaged by the founder directly. If a confirmed incident affects your data, we aim to notify you within 72 hours of confirming it, with what happened, what data was involved, and what we did about it. No legal-department stonewalling.
AI data handling
Your claim data never trains our AI models. Claimory's AI engine runs on enterprise AI providers that do not train on API requests by default, and requests are scoped to the current claim context and not retained beyond the request lifecycle. No customer claim text, photos, or customer PII is shared with ad networks, analytics vendors, or training datasets. The specific AI sub-processors we use are named in our Privacy Policy.
Leaving Claimory
Export your claims, photos, estimates, and financial records as PDF or CSV, and your core account records including messages as machine-readable JSON, at any time. Your data leaves with you. Cancel and we delete it on request.
AI, answered directly
The four questions every shop owner asks us before turning on the AI drawer.
Will the AI read my customer data?
Only when you ask it to. The AI drawer reads the specific claim you have open so it can answer in context. Nothing is shared across workspaces, and no claim data is sent to a third-party model outside of an active request you triggered.
Do you train your models on my claim data?
No. Your claim data never trains our models. AI prompts use claim context only and are never used to train provider models.
What about HIPAA? Some of my DRP paperwork has medical info.
Claimory is not a HIPAA-covered entity and is not marketed for handling protected health information. If your DRP workflow involves PHI, keep that data out of Claimory and in the carrier's or provider's HIPAA-compliant system. We treat all customer PII (name, address, phone, VIN) as sensitive and encrypt it the same way regardless.
What happens when the AI is wrong?
You are always the one sending the email, approving the supplement, or finalizing the estimate. The AI drafts and suggests. You decide. Every AI response in the drawer cites the claim context it pulled from so you can verify before acting.
Certifications, honestly
We will not claim a badge we have not earned. Here is the actual status.
SOC 2 Type II
Readiness work in progressSOC 2 Type II readiness work is in progress, and the audit engagement is planned but not yet started. Current controls (encryption at rest with AES-256, TLS 1.2+ in transit, RBAC, access review, append-only audit logging, incident response runbooks) are modeled directly after the SOC 2 trust services criteria so we can pass audit when we engage. If your shop needs proof of current controls before the report issues, request the security questionnaire from info@claimory.io.
ISO 27001
Not pursuingNot on the near-term roadmap. Controls draw from the same common security baseline.
HIPAA
Not offeredClaimory is not a HIPAA-covered entity and does not support protected health information. Keep PHI out of Claimory and in your carrier's or provider's HIPAA-compliant system.
CCPA
AlignedWe honor California Consumer Privacy Act rights. Request data access, correction, or deletion by emailing support. We respond within 45 days.
Permission levels
Every user has a defined role. Nobody sees more than they need.
Owner
Full workspace access including billing and team management
Manager
Manage claims, jobs, and team assignments
Estimator
Create and manage claims and estimates
Technician
View assigned work and update job status
Still have a security question?
Start a 14-day trial and kick the tires, or reach out and we will answer directly. Multi-location operators get a dedicated security walkthrough.
No credit card. Works with CCC ONE and Mitchell.
We read every security email. Reply within one business day, usually same day.
