← ClaimScope for Veterans

Security and privacy

How ClaimScope protects Veteran records

ClaimScope uses layered safeguards appropriate for sensitive military, medical, and benefits records. No online service can guarantee absolute security, so we distinguish controls already operating from controls still being verified before real C-file intake opens.

Controls operating now

  • Encrypted HTTPS connections to the ClaimScope site.
  • Supabase-managed email/password and passwordless email access with secure, expiring sessions.
  • Cloudflare R2 encryption for stored objects and metadata using AES-256.
  • Separate switches for document intake, automated processing, and compliance approval.
  • Matter deletion that removes active uploaded objects and associated application records.
  • No active Stripe checkout and no C-file contents sent to Stripe.
  • No use of Veteran records for advertising or model training authorized by ClaimScope.

Required before real-file intake

Sensitive-document intake remains technically locked while these controls are completed and tested:

  • Cross-account authorization and deletion tests.
  • Malware scanning and archive-bomb protections.
  • Temporary processor-file deletion after success, failure, or interruption.
  • Administrative-access review, MFA, and content-free audit logging.
  • Model endpoint, retention, and minimum-necessary transmission verification.
  • Backup and provider-log expiration documentation.

Your control

You choose whether to upload records. You may permanently delete a matter from the dashboard. ClaimScope does not sell Veteran records, use them for behavioral advertising, or provide them to Stripe. Staff access, if support access is later offered, will require the user’s explicit permission and will be logged.