Your data is yours
We never sell your data, and we never train AI models on your claim content. You can export everything you've entered at any time, and you can delete your account whenever you want — your data is permanently removed after a 30-day grace window in case of accidental deletion.
Encryption everywhere
All traffic between your device and Claim Atlas is encrypted in transit with TLS. All data — your claims, photos, notes, and reports — is encrypted at rest with AES-256. Passwords are hashed and salted; they are never stored in a form anyone, including us, can read.
One firm can never see another firm's data
Claim Atlas is multi-tenant, which means every firm gets a fully isolated workspace. Every record — every claim, file, note, and expense — is tagged to your firm, and every request is checked against your firm's identity before any data is returned. There is no shared view, and no path for one customer to reach another customer's claims or files.
Access controls & 2FA
Two-factor authentication (TOTP) is available on every account and we recommend turning it on. Within your firm, roles determine who can see and change what. Sessions expire, and administrative actions are recorded in an audit log so you can see who did what.
We never touch a card number
All billing runs through Stripe, a PCI-DSS Level 1 certified payment provider. Card details are entered directly with Stripe and never pass through or land on Claim Atlas servers.
Photos go straight to secure storage
When you upload a photo or document, it is transferred directly from your device to encrypted object storage over a short-lived, single-use secure link. Files do not sit on the application server, and stored files are only reachable by authenticated members of your firm.
Backups & reliability
Your database is backed up daily, and backups are encrypted. Infrastructure runs on Fly.io and Cloudflare — the same class of providers the largest software companies rely on — with uptime monitoring and error tracking in place so we catch problems fast.
Who helps us run the service
We keep our vendor list short and reputable. Each of these subprocessors signs a data-processing agreement with us and has a strong security track record:
| Vendor | What they do | Location |
|---|---|---|
| Cloudflare | File storage (R2) & content delivery | United States |
| Fly.io | Application & database hosting | United States |
| Stripe | Payment processing & billing | United States |
| Resend | Transactional email delivery | United States |
| Sentry | Error monitoring | United States |
| Crisp | In-app support chat | European Union |
Compliance & certifications
Claim Atlas is a young company and we're transparent about where we are. We are not yet SOC 2 audited, but the controls a SOC 2 audit looks for — encryption, tenant isolation, access controls, audit logging, backups, and vendor management — are already built into the product, and a formal audit is on our roadmap. If your organization requires it, we're happy to complete security questionnaires and sign a data-processing agreement. Just reach out.
Reporting a problem
If you believe you've found a security vulnerability, please email security@claim-atlas.net. We read every report and will respond quickly. Please give us a reasonable chance to fix an issue before disclosing it publicly.
Questions
Security or privacy questions from a prospective customer? Email hello@claim-atlas.net and we'll walk you through anything you need for your due diligence.