Security & Compliance
Built for the trust requirements of the insurance industry.
A claim packet contains claimant SSNs, health records, and financial details. Claimloom processes that data to run its checks — and stops there. We do not store claim content, we do not retain PII, and we are not a claims record system.
How claim data moves through Claimloom
Four architectural decisions that define how we handle the most sensitive documents your operation produces.
On compliance framing: Claimloom is designed with SOC 2 controls in mind and our architecture reflects data-minimization principles consistent with HIPAA's minimum necessary standard. We have not undergone formal SOC 2 Type II certification at this stage. We do not claim HIPAA-covered entity or business associate certification. Carriers and TPAs with specific compliance evaluation requirements should contact us — we share controls documentation during vendor assessments.
Where claim data lives — and where it doesn't.
The claim packet flows in one direction through Claimloom. Structured check results flow out. Raw documents and claimant PII are discarded at the end of the processing window.
Questions about our security posture?
We share controls documentation and data-handling architecture details with carriers and TPAs during vendor evaluation. Contact us to start the conversation — we respond within one business day.