Security at LossStack
Claim data is sensitive. LossStack is designed with access control, encryption, audit traceability, and organization-level isolation from the ground up.
Access control
- Role-based permissions configured at the organization level
- Claims and data are scoped to your organization only
- Client portal access is controlled by token-gated secure links
- Tokens are never exposed in URLs after initial access
- Portal access can be revoked or regenerated at any time by your team
Data protection
- Claim data is stored in access-controlled, encrypted infrastructure
- Attachments and documents are stored with server-side encryption
- Presigned upload URLs are scoped and time-limited
- No claim data is shared across organizations
- Data is isolated by organization at the database level
Audit and traceability
- All claim-level actions are logged to an auditable activity history
- Atlas measurement orders, status changes, and deliveries are logged
- Client portal interactions (messages, approvals, document access) are recorded
- Team permission changes and invitations are audit-logged
- Signed document events are recorded with timestamps
API and integration security
- All API endpoints require authenticated sessions or API tokens
- Mobile (LossStack Field) requests require signed API tokens scoped to your organization
- Public routes (client portal, health checks) are explicitly allowlisted — no accidental exposure
- No claim data is returned from unauthenticated endpoints
Security disclosures
This page describes the general security architecture of LossStack. It is not a formal security audit, penetration test report, or compliance certification document. If you have specific security requirements for an Enterprise evaluation, contact us to discuss.
To report a security vulnerability, email security@lossstack.com.
Have specific security questions for an Enterprise evaluation?