Skip to the page
Security

Patient data, handled like patient data.

How Claim House separates test from live, controls who can do what, and keeps a record of it.

Access

Who can do what

Roles for every teammate

Owner, admin, developer and viewer. The rules are enforced in the database, not only on the screen.

Scoped API keys

Each key has read or submit permissions and a mode. The full key is shown once, and you can revoke it at any time.

Test and live kept apart

A test key can only ever reach the sandbox.

An audit trail

Changes to the account are recorded with who made them and when.
Data in motion

What leaves and what comes in

Signed webhooks

Every delivery carries a signature you can verify. The signing secret is shown once.

Safe retries

Idempotency keys on every write, so a retry never sends a claim twice.

SFTP with a published host key

Batch partners verify the server by its fingerprint before sending a file.

Uploads are rewritten

Attachment images are checked by size and rewritten before they are stored.
AI agents

Agents get the same rules as people

Same key, same permissions

The MCP server checks the same key, permissions and validation as the API. A key without the permission gets refused and nothing runs.

Sandbox by default

An agent with a test key cannot touch real patient data.

Every tool call is logged

Requests through the MCP server show on the Developers page. The log never holds the arguments.

Security questions for a review or questionnaire: talk to us.

Build for free. Pay when you go live.