Security
Reclaim handles protected health information, and the platform is built around that responsibility from the infrastructure up.
Encryption everywhere
All data is encrypted in transit with TLS and at rest with managed KMS keys, including databases, document storage, and backups.
Isolated infrastructure
Reclaim runs in its own dedicated cloud account and private network. Services communicate over private endpoints, and outbound traffic is restricted to what the platform needs.
Access control
Single sign-on with enforced authentication, role-based permissions inside the product, and least-privilege access for our own team and systems.
Audit logging
Key actions on claims, disputes, and documents are recorded in an audit log, so there is always an answer to who did what, and when.
PHI-aware operations
Logging and monitoring pipelines are built to keep PHI out of operational tooling: allowlisted log fields with layered redaction before anything leaves our infrastructure.
Business associate agreements
Our core cloud infrastructure operates under a business associate agreement, and we sign BAAs with our customers as part of onboarding.
We run a continuous security and compliance program, including independent review of our infrastructure and practices. Questions, or need our security documentation for procurement? Write to agent@goreclaim.ai.