Security at Claimbound
This page describes our current practices in plain terms. In keeping with our own evidence standard, it makes no verdict claims about ourselves — it states what we do, what we hold, and what we don't yet have. It is updated as reality changes, with the date below.
What we do
- Hardware-key multi-factor authentication on the accounts that touch customer data.
- Customer evidence lives in isolated, per-engagement storage with named-person access — never in our code repositories, ticketing, or logs.
- Read-only access to customer systems, scoped in writing before it is granted, revocable by the customer at any time.
- Source code is not retained: facts are extracted, code is discarded, snippets require per-snippet consent.
- Credentials and secrets are never collected; if encountered, they are redacted and the customer is told.
- Delivered artifacts are SHA-256 hashed and recorded in an append-only issuance log, so any copy can be integrity-checked.
- Deletion on request: customer evidence and claim content deleted within 35 days, confirmed to you in writing (what survives — non-confidential issuance metadata — is disclosed up front).
- AI assistance operates under no-training API terms, only on content already classified in the claim registry, and cannot introduce facts into deliverables.
What we don't yet have
- No third-party attestations of our own (SOC 2 Type II is planned; when we hold one, it will be listed here with issuer and period — not before).
- No bug-bounty program yet; vulnerability reports are welcome at hello@claimbound.com and acknowledged within 2 business days.
Subprocessors
Current subprocessors that may process customer-related data:
- Google Workspace (evidence storage, email, documents)
- Dropbox Sign (contracts and approval records)
- Stripe (billing — payment card data is handled by Stripe; we never see card numbers)
- Anthropic (AI drafting assistance under no-training API terms, classified content only)
This list changes only with advance notice to active customers, per Customer Data Rights.
Signing keys
Governance releases and issued-artifact records will be signed; key fingerprints will be published here once provisioned, so anyone can check our records without trusting us.