01 / Encryption
Protected at rest
Google Cloud encrypts customer content at rest using AES-256 by default. Core GCP storage and secrets use Google-managed encryption keys.
Google Cloud encryption documentationSecurity & compliance
Restoria protects sensitive claim work with Google Cloud infrastructure, firm-scoped access, documented safeguards, and controlled AI processing.
How protection fits together
Google protects the underlying cloud platform. Restoria configures and operates the application controls that determine who can reach each firm, project, file, and AI workflow.
Customers reach Restoria through HTTPS-protected web and API endpoints.
Every protected request is tied to an authenticated user and active firm.
The API verifies firm, project, file, chat, and action permissions.
Claim context enters isolated, purpose-limited AI workflows for licensed review.
Google Cloud security
Restoria’s primary application infrastructure runs on Google Cloud in US regions. These platform protections are combined with Restoria’s application and organizational controls.
01 / Encryption
Google Cloud encrypts customer content at rest using AES-256 by default. Core GCP storage and secrets use Google-managed encryption keys.
Google Cloud encryption documentation02 / Transit
Customer connections use HTTPS. Google protects customer data moving within its networks with authenticated encryption controls.
Google Cloud transit protections03 / Compute
Restoria’s API runs on Cloud Run, where Google applies hardware-backed and software sandboxing layers between workloads.
Cloud Run security design04 / Storage
Claim files are stored in a non-public Cloud Storage bucket. Uniform bucket-level access keeps object permissions under Google Cloud IAM.
Cloud Storage access controls05 / Secrets
Production credentials are bound from Secret Manager to the runtime identity rather than committed to source or embedded in the browser application.
Secret Manager encryption06 / Delivery
The production deployment exchanges GitHub identity for short-lived Google Cloud credentials and proceeds only after the main quality gate succeeds.
Workload Identity FederationIdentity & tenant separation
The firm is Restoria’s tenant boundary. The API—not a hidden button or browser route—enforces who may see and change each resource.
Operational safeguards
Technical controls are supported by policies, assigned responsibility, workforce practices, vendor oversight, and response planning.
Privacy, AI & retention
Restoria sends the inputs needed to perform requested AI features. Confidential claim data is not used to train AI models without explicit consent.
AI features organize information and prepare administrative or drafting work. They do not make professional adjusting decisions or remove licensed review.
After termination, customers have a 30-day export period. User content is then removed from active systems, with backup copies deleted within 90 days.
Firms may request a read-only compliance hold for longer statutory recordkeeping. Each firm remains responsible for its own retention obligations.
The Privacy Policy provides the complete provider, collection, retention, and rights disclosures. The Acceptable Use Policy defines what customers may process through Restoria.
Compliance support
Restoria maintains administrative, technical, and physical safeguards designed to support applicable GLBA and FTC Safeguards Rule obligations.
The security program includes assigned ownership, risk review, safeguard implementation, provider oversight, control testing, and incident response.
Restoria supports access, correction, deletion, and opt-out requests as described in the Privacy Policy, including recognized Global Privacy Control signals.
Connected Google account data is used to provide requested service features and is handled under Google API Services User Data Policy requirements.
Restoria supports firm workflows; each public adjuster remains responsible for licensing, professional judgment, source verification, and recordkeeping duties.
Security review
Restoria’s primary application infrastructure runs on Google Cloud in US regions. The Privacy Policy identifies the other providers used for authentication, structured data, AI processing, communications, and supporting services.
Customer connections use HTTPS. Google Cloud encrypts customer content at rest by default, including data stored in Cloud Storage and Secret Manager.
Restoria does not use confidential claim data to train AI models without explicit customer consent.
Yes. Customers receive a 30-day export window after termination and may request a read-only compliance hold for longer statutory retention needs.
Email [email protected] with the affected surface, steps to reproduce, potential impact, and a safe way to reach you. Do not include live customer claim data in the report.
Need a closer review?
Send your security questionnaire, architecture question, or incident report to the team responsible for Restoria’s security program.
Security information last reviewed July 22, 2026.