Security Policy
Last Updated: July 4, 2026
1. Commitment to Security
XactaClaim is operated by XactaClaim LLC, a U.S.-based software company located at 50 Adams St., Ste 152, Milton, MA 02186, United States. XactaClaim provides claim documentation, communication, and workflow software for claim professionals and their teams.
XactaClaim is not an insurance carrier, law firm, public adjusting firm, or licensed claims provider. XactaClaim does not provide legal advice, insurance advice, public adjusting services, claim valuation opinions, or claim outcome guarantees.
For business, privacy, or support questions, contact XactaClaim at hello@xactaclaim.com.
XactaClaim is not an insurance carrier, law firm, public adjusting firm, or licensed claims provider. XactaClaim does not provide legal advice, insurance advice, public adjusting services, claim valuation opinions, or claim outcome guarantees.
At XactaClaim, we treat the security of your data—and the data of your clients—with the utmost seriousness. Our infrastructure is built upon enterprise-grade cloud providers utilizing modern security practices.
2. Data Encryption
All data processed by XactaClaim is encrypted both in transit and at rest:
- In Transit: All communications between your browser and our servers, as well as between our servers and our third-party sub-processors, are encrypted using TLS 1.2 or higher.
- At Rest: Databases, document storage, and backups are encrypted at rest using industry-standard encryption managed by Google Cloud Platform.
3. Access Controls: Staff and Client Portal
Staff users authenticate through Firebase Auth with role-based workspace access. Client portal access is PIN-based on a specific claim file and does not use staff Firebase accounts.
Portal sessions may use browser session storage for convenience, expire after approximately twelve (12) hours, and are re-verified with our servers before claim data is shown. Clients and workspace users should not share portal PINs, phone access codes, or portal links broadly.
Claim data is scoped to agency workspaces and claim records according to application access rules. Internal claim notes and AI Claim Brief outputs are staff-only and are not exposed through the client portal. Users should protect staff credentials and portal access details on their devices.
Staff users may access workspace data through the web application and, on eligible Pro or Premium plans, through the mobile companion using the same authenticated APIs subject to role and plan checks. Email verification may be required before workspace access is granted.
Account security features may include email verification, password sign-in, and linking or unlinking Google or Apple sign-in methods. Users should keep at least one sign-in method connected and protect linked accounts.
3A. Staff Mobile Companion Security
The XactaClaim mobile companion is a staff-only application for eligible Pro or Premium workspace users. It is not a client mobile app. Client portal access remains PIN-based through the web browser.
- Authenticated access: Mobile uses the same Firebase-authenticated staff accounts as the web workspace, subject to email verification, workspace membership, plan entitlement, and role checks.
- No AI keys on device: The mobile companion does not store Google Gemini or other AI provider API keys on the device.
- Server-side AI: AI Claim Brief and other AI-assisted features invoked from mobile are processed through XactaClaim server APIs. Staff must review outputs before acting or sharing.
- Staff-only data boundaries: Internal Claim Notes and AI Claim Brief outputs remain staff-only and are not exposed through the client portal.
- Connectivity required: Offline mode is not implemented. Mobile and web require network access to authenticate and retrieve workspace data.
- Release variance: Mobile features may vary by app release and may not include every web workflow.
Protect mobile devices with OS-level security (screen lock, biometrics where appropriate), avoid shared personal devices for claim work, sign out when finished on shared hardware, and notify your workspace administrator if a device or staff account may be compromised.
4. Artificial Intelligence (AI) — Security & Data Handling
XactaClaim includes AI-assisted features that may help summarize claim information, review uploaded policy documents, compare estimates, analyze photos, or generate workflow suggestions. When a user chooses to use these features, relevant Customer Content may be processed by third-party AI service providers to return the requested output. AI outputs are for workflow assistance only and may be incomplete or inaccurate. Users are responsible for reviewing all AI outputs before relying on them. We do not use Customer Content to train XactaClaim-owned foundation models.
XactaClaim uses configured third-party AI service providers (such as Google Gemini and related Google AI services) to power assistive analysis, summarization, drafting, and Q&A features when enabled. This section describes security and data-handling constraints for those features. For acceptable use and user responsibilities, see our Terms of Service — Artificial Intelligence (AI). For inputs, outputs, and subprocessors, see our Privacy Policy — Artificial Intelligence (AI).
Processing architecture
AI-assisted features invoked from the web workspace or mobile companion are processed through XactaClaim server APIs under workspace authentication and role checks. The mobile companion does not store Google Gemini or other AI provider API keys on the device and does not call third-party AI providers directly. AI features may use truncated or summarized claim context (such as note excerpts, task descriptions, document metadata, and saved analyses) rather than full raw files for every request.
Provider data constraints
We enforce data-handling constraints on configured AI services, including:
- Zero Retention for Training: We utilize enterprise API endpoints for configured AI providers (such as Google Gemini). Under these arrangements, your content is NOT used to train their public foundational models.
- Ephemeral Processing: When documents, images, or transcripts are passed to AI for analysis, content is processed to generate a response and handled according to provider retention constraints.
- Agency scoping: AI requests are tied to authenticated workspace access controls; claim data is not exposed across agencies through AI features.
Staff-only boundaries and human review
AI-assisted features such as Claim Copilot, Morning Brief, and AI Claim Brief may generate staff-facing summaries and responses. AI Claim Brief outputs and internal claim notes are intended for staff workspace users and are not exposed to client portal sessions. AI outputs are assistive only — users must review and verify AI-generated content before relying on it or sharing it externally.
5. Shared Responsibility Model
Security is a shared responsibility between XactaClaim and you, the user. While we secure the infrastructure, you must secure your access:
We are not liable for unauthorized access resulting from compromised user credentials, shared passwords, shared portal PINs or access codes, phished accounts, or unsecured devices on your end. You are strictly responsible for maintaining the confidentiality of your login credentials and portal access details.
6. Infrastructure and Compliance
We use cloud infrastructure and service providers to host, secure, operate, and support XactaClaim. These providers may process Customer Content or related metadata only as needed to provide their services to XactaClaim. Examples may include hosting, database, storage, authentication, payment processing, email, SMS/MMS, voice, analytics, and AI service providers.
Our primary infrastructure is hosted on Google Cloud Platform (GCP) via Firebase. GCP undergoes regular independent third-party audits to verify their security, privacy, and compliance controls, including SOC 1, SOC 2, and ISO/IEC 27001.
References to Google Cloud, Firebase, SOC 2, ISO, or similar infrastructure controls refer to underlying provider security programs and do not mean XactaClaim itself has completed those certifications.