Security
Security built into the claim workflow.
LossStack handles sensitive business, property, and claim information. Security is designed into the platform through organization-level data isolation, authentication, access controls, encryption, auditability, and secure infrastructure practices.
Last updated: September 2, 2026
Data isolation
- Organization-level tenant isolation
- Claims scoped to authorized organizations and users
- Database authorization controls
- No intentional cross-organization claim visibility
Identity & access
- Secure authentication and MFA support
- Role-based permissions and organization/user authorization
- Session controls
- Permission-aware claim access
Data protection
- Encryption in transit
- Infrastructure-provided storage protections at rest
- Secure storage for claim photos and documents
- Scoped or time-limited upload and access mechanisms where applicable
- Sensitive claim data protected from public browsing
Application security
- Authenticated APIs and server-side authorization validation
- Narrowly restricted public routes
- Input validation
- Secrets managed outside source code
- Server-side access controls for sensitive operations
Mobile security
- Authenticated LossStack Field access
- Organization-scoped mobile APIs
- Secure synchronization with LossStack One
- Mobile sessions governed by account permissions
Auditability
- Claim activity history
- Assignment and status tracking
- Document and signature events
- Permission and invitation events
- Relevant portal activity and operational traceability
Client portal
- Intentionally limited client-facing access
- No unrestricted workspace access for portal users
- Controlled and revocable access
- Only explicitly client-facing information exposed
File & photo security
- Claim-linked storage
- Controlled file access and scoped upload/download flows
- Organization-based authorization
- No publicly browsable claim library
AI & data
AI-assisted LossStack functions process information as necessary to provide features requested by authorized users. Those workflows remain subject to LossStack access controls and privacy practices. Users should review AI-assisted output before relying on it.
Infrastructure & operations
LossStack applies production environment controls, keeps secrets outside source code, performs dependency and security updates, uses monitoring and logging, maintains backup and recovery processes where implemented, and applies least-privilege principles where appropriate.
Security program and compliance positioning
LossStack is building its security program toward the controls and operational maturity expected of modern SaaS platforms, including work toward SOC 2 readiness. References to security readiness or future compliance initiatives do not represent a certification unless LossStack expressly states that a certification has been completed.
Responsible disclosure
Report a suspected vulnerability to security@lossstack.com. Include enough detail for us to reproduce and assess the issue.
Security researchers must not:
- Access or retain customer information.
- Perform destructive testing or degrade service availability.
- Use social engineering against customers, employees, or vendors.
- Publicly disclose a vulnerability before LossStack has had a reasonable opportunity to investigate and remediate it.
Have specific security questions for an Enterprise evaluation?
Contact Us