Security you can build a practice on.
Claim files hold policy numbers, loss details, and personal information about insureds. This page describes the controls that are implemented today, in plain terms — not a roadmap and not a badge.
Who can open a claim file, and what the record keeps.
Your claim files hold policy numbers, loss details, and personal information about insureds — and you are the one answerable for them. These are the controls implemented today.
- Role-based access controlOwners, managers, Reviewer / Quality Assurance Analysts, and staff see what their role permits.
- Organization isolationEach organization's data is scoped to that organization, with per-record visibility controls inside it.
- Encryption in transit & at restTraffic is served over TLS; stored data is encrypted at rest in the managed database and file storage.
- Activity & audit historyMeaningful actions on a claim file are recorded with a timestamp and an actor.
- Secure authenticationAuthenticated sessions, least-privilege access to internal systems, and secrets kept out of source code.
- Controlled permissionsAssignment, review, and approval are separate rights, each granted on its own.
Role-based access control
Owners, managers, Reviewer / Quality Assurance Analysts, and staff see what their role permits.
Organization isolation
Each organization's data is scoped to that organization, with per-record visibility controls inside it.
Encryption in transit & at rest
Traffic is served over TLS; stored data is encrypted at rest in the managed database and file storage.
Activity & audit history
Meaningful actions on a claim file are recorded with a timestamp and an actor.
Secure authentication
Authenticated sessions, least-privilege access to internal systems, and secrets kept out of source code.
Controlled permissions
Assignment, review, and approval are separate rights, each granted on its own.
- What ClaimFileHQ stores
- Claim files and the records attached to them — client and contact details, claim and policy identifiers, loss information, documents, photographs, notes, tasks, scheduling data, communications, and billing records — plus the account information of the users in your organization.
- Who can reach it inside your organization
- Access is determined by role. On the Partner Network plan, everything dispatch sends out is visible to all parties on the file, while the assigned professional's photos and email correspondence stay private to them and each document they upload carries its own visibility setting. A professional's own clients and files, brought in outside the network, are not part of the organization's pool.
- Who can reach it inside ClaimFileHQ
- Access to production systems is limited to the personnel who need it to operate and support the service, and application secrets are held in environment configuration rather than in source code.
- Sub-processors
- ClaimFileHQ runs on third-party cloud hosting, database, storage, and communications providers. Those providers process data on our behalf under their own agreements. Write to us for the current list.
Bringing us through procurement?
Firms that handle carrier work are often asked to document how their vendors protect claim data. We are happy to work through a security review or a vendor questionnaire directly, and to answer specific questions about how your organization's data would be stored, segregated, and accessed.
Write to support@claimfilehq.com and tell us what your reviewer needs.
Reporting a vulnerability
If you believe you have found a security issue in ClaimFileHQ, email support@claimfilehq.com with the details and how to reproduce it. Please give us a reasonable opportunity to investigate and remediate before disclosing publicly.
