01 / Encryption
Protected at rest
Google Cloud encrypts customer content at rest using AES-256 by default. Core GCP storage and secrets use Google-managed encryption keys.
Google Cloud encryption documentationSecurity & compliance
Restoria protects sensitive claim work with Google Cloud infrastructure, firm-scoped access, and controlled processing.
How protection fits together
Google protects the underlying cloud platform. Restoria configures and operates the application controls that determine who can reach each firm, project, file, and AI workflow.
Customers reach Restoria through HTTPS-protected web and API endpoints.
Every protected request is tied to an authenticated user and active firm.
The API verifies firm, project, file, chat, and action permissions.
Claim context enters isolated, purpose-limited AI workflows for licensed review.
Google Cloud security
Restoria’s primary application infrastructure runs on Google Cloud in US regions. These platform protections are combined with Restoria’s application and organizational controls.
01 / Encryption
Google Cloud encrypts customer content at rest using AES-256 by default. Core GCP storage and secrets use Google-managed encryption keys.
Google Cloud encryption documentation02 / Transit
Customer connections use HTTPS. Google protects customer data moving within its networks with authenticated encryption controls.
Google Cloud transit protections03 / Compute
Restoria’s API runs on Cloud Run, where Google applies hardware-backed and software sandboxing layers between workloads.
Cloud Run security design04 / Storage
Claim files are stored in a non-public Cloud Storage bucket. Uniform bucket-level access keeps object permissions under Google Cloud IAM.
Cloud Storage access controls05 / Secrets
Production credentials are bound from Secret Manager to the runtime identity rather than committed to source or embedded in the browser application.
Secret Manager encryption06 / Delivery
The production deployment exchanges GitHub identity for short-lived Google Cloud credentials and proceeds only after the main quality gate succeeds.
Workload Identity FederationIdentity & tenant separation
The firm is Restoria’s tenant boundary. The API—not a hidden button or browser route—enforces who may see and change each resource.