Security & Compliance

ClaimNorth Inc. is pursuing SOC 2 Type II with anticipated report-in-hand within 5–7 months. This page is the live source of truth for our security posture — last updated 2026-05-27.

Compliance program
SOC 2 Type II
Operating since
2026
Hosting
Cloudflare edge
Encryption
TLS 1.2+ in transit

Trust Services Criteria (AICPA TSC) — current posture

Criteria areaImplementationStatus
CC6.1 Logical accessPassword + 2FA TOTP, SAML 2.0 + OIDC SSO, role-based access✓ Operational
CC6.2 User provisioningInvite-token-based onboarding with role assignment + audit logging✓ Operational
CC6.3 Access lifecycleActive session tracking, owner-visible revoke at /settings/sessions✓ Operational
CC6.4 Stale access2FA re-verification after 7 days inactivity on sensitive actions✓ Operational
CC6.6 Authenticated integrationsHMAC-SHA256 signed outbound + verified inbound webhooks✓ Operational
CC6.7 Encryption in transitTLS 1.2+ enforced via HSTS + Cloudflare edge✓ Operational
CC6.8 Encryption at rest2FA secrets + backups column-level encrypted (Fernet); full DB SQLCipher migration on roadmap◐ Partial
CC7.1 Continuous monitoringSim harness + p99 dashboard + sentry-compatible exception capture✓ Operational
CC7.2 Backups + restoreDaily encrypted backups with quarterly restore drill✓ Operational
CC7.3 Incident responseDocumented IR plan with 4-tier severity classification✓ Operational
CC8.1 Change managementWave-numbered change log + Source-of-Truth mirror✓ Operational
CC9.1 Vendor managementVendor inventory at /admin/vendors with SOC 2 status tracking✓ Operational
A1.2 Availability — backupSame as CC7.2✓ Operational
A1.3 Availability — BCPBCP/DR plan with 4h RTO, 24h RPO targets✓ Operational
C1.1 Confidentiality protectionOrg-level data isolation enforced before every request✓ Operational
C1.2 Confidentiality disposal30-day soft-delete + cron purge with audit trail✓ Operational
P1.1 Privacy notice/privacy, /terms, /cookies✓ Operational
P5.2 Data portabilityOwner-requestable per-org ZIP export (GDPR Art. 20)✓ Operational
P6.1 Right to deletionCustomer data-deletion request flow with 7-day cooling-off (GDPR Art. 17)✓ Operational

Encryption

In transit: All connections to app.claimnorth.com require TLS 1.2 or higher, enforced via HSTS preload. Cloudflare terminates TLS at the edge with modern cipher suites.

At rest: 2FA TOTP secrets and backup files are encrypted at the application layer using Fernet (AES-128 + HMAC). The full SQLite database is currently stored with file-permission isolation (mode 0600, service-user-only); SQLCipher full-database AES-256 encryption is planned for completion within 90 days.

Key management: Encryption keys are stored in /etc/default/scopeforge-estimator with file mode 0600 and service-user ownership. Keys are rotated annually or on suspected compromise.

Authentication options

  • Password + 2FA TOTP — required for owners; available to all roles via authenticator app
  • SAML 2.0 SSO — for enterprise customers with Okta, Auth0, Azure AD, Google Workspace, etc.
  • OIDC SSO — same enterprise IdPs via OpenID Connect
  • Recovery codes — single-use bcrypt-hashed at 2FA enrollment
  • API tokens — per-org with scope restriction and rate limits

SMS-based 2FA is not supported (SIM-swap risk).

Customer rights

  • Export your data at any time — JSON + ZIP via /settings/export (GDPR Article 20)
  • Delete your account — 7-day cooling-off, full hard-delete or anonymization (GDPR Article 17)
  • Audit log — every action against your data is timestamped and visible at /settings/audit-log
  • Active sessions — list and revoke at /settings/sessions
  • API tokens — create, scope, and revoke at /settings/api-tokens

Sub-processors

ClaimNorth uses the following third-party services to deliver the product. Each is bound by a Data Processing Agreement (DPA). See /security/sub-processors for the full list with data flows.

Reporting a vulnerability

If you believe you have found a security vulnerability in ClaimNorth, please email security@claimnorth.com. We respond within 1 business day. We do not yet operate a paid bug bounty but credit researchers in our acknowledgments page (when first researcher discloses).

Please give us reasonable time to remediate before public disclosure.

Live source: the /admin/soc2 page (authed) is the operational scoreboard auto-populated from runtime checks. This page is the public-facing summary. Last reviewed 2026-05-27, next review 2027-05-27.

SOC 2 Type II report: Anticipated availability 5–7 months from this page's effective date. Email security@claimnorth.com to be notified when the report is published.