Security

Reclaim handles protected health information, and the platform is built around that responsibility from the infrastructure up.

Encryption everywhere

All data is encrypted in transit with TLS and at rest with managed KMS keys, including databases, document storage, and backups.

Isolated infrastructure

Reclaim runs in its own dedicated cloud account and private network. Services communicate over private endpoints, and outbound traffic is restricted to what the platform needs.

Access control

Single sign-on with enforced authentication, role-based permissions inside the product, and least-privilege access for our own team and systems.

Audit logging

Key actions on claims, disputes, and documents are recorded in an audit log, so there is always an answer to who did what, and when.

PHI-aware operations

Logging and monitoring pipelines are built to keep PHI out of operational tooling: allowlisted log fields with layered redaction before anything leaves our infrastructure.

Business associate agreements

Our core cloud infrastructure operates under a business associate agreement, and we sign BAAs with our customers as part of onboarding.

We run a continuous security and compliance program, including independent review of our infrastructure and practices. Questions, or need our security documentation for procurement? Write to agent@goreclaim.ai.