Last updated 15 August 2026
Security Overview
Claimsight is designed for controlled insurance evidence pilots where access is limited to invited claimants, authorised customer users, and configured API credentials.
How access is controlled
- Customer users authenticate with application accounts and team membership controls.
- Customer API access uses organisation credentials or scoped access tokens, with object-level session checks.
- Claimant upload access is invite-token based and claimant tokens are limited to claimant evidence submission flows.
- Unauthorised result and asset requests return the same not-found style response as missing objects.
Evidence and audit controls
- Evidence originals, generated reports, and exports are protected by authenticated access controls and are not publicly accessible.
- Access to session results, reports, exports, and human review updates is audit logged.
- Sensitive device identifiers are encrypted at the application storage boundary.
- Operational alerts can notify configured recipients about analysis, report, or customer-notification failures.
Automated indicators and human review
Manipulation confidence reflects the strength of image-analysis indicators. It is not a calibrated probability or determination of fraud and must support, not replace, human review. Claimsight does not determine liability, coverage, or claim outcome. Insurer users can record a separate human review disposition on a claim session.
Vulnerability reporting
Please report suspected vulnerabilities to security@claimsight.io. Include the affected URL, reproduction steps, and whether any personal data may be involved. Do not access, alter, delete, or exfiltrate data that is not yours.
A machine-readable security contact is available at /.well-known/security.txt. The disclosure policy is published at vulnerability disclosure.
Certifications
This page does not claim any security certification unless it is separately confirmed in a signed customer agreement or official certificate.