LossStack is expanding — Echo, Atlas, Sign, Restoration, Build, and more are coming together in one connected platform. Request early access →
LossStack

Security

Security built into the claim workflow.

LossStack handles sensitive business, property, and claim information. Security is designed into the platform through organization-level data isolation, authentication, access controls, encryption, auditability, and secure infrastructure practices.

Last updated: September 2, 2026

Data isolation

  • Organization-level tenant isolation
  • Claims scoped to authorized organizations and users
  • Database authorization controls
  • No intentional cross-organization claim visibility

Identity & access

  • Secure authentication and MFA support
  • Role-based permissions and organization/user authorization
  • Session controls
  • Permission-aware claim access

Data protection

  • Encryption in transit
  • Infrastructure-provided storage protections at rest
  • Secure storage for claim photos and documents
  • Scoped or time-limited upload and access mechanisms where applicable
  • Sensitive claim data protected from public browsing

Application security

  • Authenticated APIs and server-side authorization validation
  • Narrowly restricted public routes
  • Input validation
  • Secrets managed outside source code
  • Server-side access controls for sensitive operations

Mobile security

  • Authenticated LossStack Field access
  • Organization-scoped mobile APIs
  • Secure synchronization with LossStack One
  • Mobile sessions governed by account permissions

Auditability

  • Claim activity history
  • Assignment and status tracking
  • Document and signature events
  • Permission and invitation events
  • Relevant portal activity and operational traceability

Client portal

  • Intentionally limited client-facing access
  • No unrestricted workspace access for portal users
  • Controlled and revocable access
  • Only explicitly client-facing information exposed

File & photo security

  • Claim-linked storage
  • Controlled file access and scoped upload/download flows
  • Organization-based authorization
  • No publicly browsable claim library

AI & data

AI-assisted LossStack functions process information as necessary to provide features requested by authorized users. Those workflows remain subject to LossStack access controls and privacy practices. Users should review AI-assisted output before relying on it.

Infrastructure & operations

LossStack applies production environment controls, keeps secrets outside source code, performs dependency and security updates, uses monitoring and logging, maintains backup and recovery processes where implemented, and applies least-privilege principles where appropriate.

Security program and compliance positioning

LossStack is building its security program toward the controls and operational maturity expected of modern SaaS platforms, including work toward SOC 2 readiness. References to security readiness or future compliance initiatives do not represent a certification unless LossStack expressly states that a certification has been completed.

Responsible disclosure

Report a suspected vulnerability to security@lossstack.com. Include enough detail for us to reproduce and assess the issue.

Security researchers must not:

  • Access or retain customer information.
  • Perform destructive testing or degrade service availability.
  • Use social engineering against customers, employees, or vendors.
  • Publicly disclose a vulnerability before LossStack has had a reasonable opportunity to investigate and remediate it.

Have specific security questions for an Enterprise evaluation?

Contact Us