Security & compliance

Security for the claim file.

Restoria protects sensitive claim work with Google Cloud infrastructure, firm-scoped access, documented safeguards, and controlled AI processing.

  • Primary infrastructure on Google Cloud
  • Firm-scoped application access
  • Written information security program
Layered claim folders protected by a bronze shield beside a mapped Google Cloud network.

How protection fits together

One control system across infrastructure and claim work.

Google protects the underlying cloud platform. Restoria configures and operates the application controls that determine who can reach each firm, project, file, and AI workflow.

  1. 01 Encrypted connection

    Customers reach Restoria through HTTPS-protected web and API endpoints.

  2. 02 Authenticated firm

    Every protected request is tied to an authenticated user and active firm.

  3. 03 Authorized claim context

    The API verifies firm, project, file, chat, and action permissions.

  4. 04 Controlled processing

    Claim context enters isolated, purpose-limited AI workflows for licensed review.

Google Cloud security

A hardened cloud foundation.

Restoria’s primary application infrastructure runs on Google Cloud in US regions. These platform protections are combined with Restoria’s application and organizational controls.

01 / Encryption

Protected at rest

Google Cloud encrypts customer content at rest using AES-256 by default. Core GCP storage and secrets use Google-managed encryption keys.

Google Cloud encryption documentation

02 / Transit

Protected while moving

Customer connections use HTTPS. Google protects customer data moving within its networks with authenticated encryption controls.

Google Cloud transit protections

03 / Compute

Isolated application runtime

Restoria’s API runs on Cloud Run, where Google applies hardware-backed and software sandboxing layers between workloads.

Cloud Run security design

04 / Storage

Private claim-file storage

Claim files are stored in a non-public Cloud Storage bucket. Uniform bucket-level access keeps object permissions under Google Cloud IAM.

Cloud Storage access controls

05 / Secrets

Managed application secrets

Production credentials are bound from Secret Manager to the runtime identity rather than committed to source or embedded in the browser application.

Secret Manager encryption

06 / Delivery

Short-lived deployment identity

The production deployment exchanges GitHub identity for short-lived Google Cloud credentials and proceeds only after the main quality gate succeeds.

Workload Identity Federation

Identity & tenant separation

Access follows the firm and the work.

The firm is Restoria’s tenant boundary. The API—not a hidden button or browser route—enforces who may see and change each resource.

Firm-scoped authorization
User-supplied firm identifiers are not trusted. Project-backed resources derive their firm from the authorized project.
Role-based administration
Owners manage firm identity, membership, billing, and destructive actions. Firm adjusters share operational claim work under defined permissions.
Private user context
Chats and personal integrations remain private to their owner even when related project files are shared within the firm.
Scoped sandbox credentials
Isolated processing environments receive short-lived credentials restricted to one authorized project directory, not a reusable Google service-account key.
Change attribution
Consequential claim-data changes retain the acting user and source context for review and accountability.

Operational safeguards

A documented security program.

Technical controls are supported by policies, assigned responsibility, workforce practices, vendor oversight, and response planning.

  • GovernanceWritten Information Security Program and designated GLBA Qualified Individual
  • WorkforceBackground checks, security training, and mandatory workforce MFA
  • AccessRole-based controls and periodic access reviews
  • VendorsSecurity assessment and oversight of service providers
  • ResponseDocumented incident-response procedures and notification workflows
  • ContinuityBusiness-continuity and disaster-recovery planning

Privacy, AI & retention

Claim data stays tied to the service you requested.

Controlled AI processing

Restoria sends the inputs needed to perform requested AI features. Confidential claim data is not used to train AI models without explicit consent.

Professional review remains required

AI features organize information and prepare administrative or drafting work. They do not make professional adjusting decisions or remove licensed review.

Defined account lifecycle

After termination, customers have a 30-day export period. User content is then removed from active systems, with backup copies deleted within 90 days.

Retention support

Firms may request a read-only compliance hold for longer statutory recordkeeping. Each firm remains responsible for its own retention obligations.

Compliance support

Controls designed around claim-data obligations.

Restoria maintains administrative, technical, and physical safeguards designed to support applicable GLBA and FTC Safeguards Rule obligations.

GLBA safeguards

The security program includes assigned ownership, risk review, safeguard implementation, provider oversight, control testing, and incident response.

Privacy rights

Restoria supports access, correction, deletion, and opt-out requests as described in the Privacy Policy, including recognized Global Privacy Control signals.

Google API Limited Use

Connected Google account data is used to provide requested service features and is handled under Google API Services User Data Policy requirements.

Shared customer responsibility

Restoria supports firm workflows; each public adjuster remains responsible for licensing, professional judgment, source verification, and recordkeeping duties.

Security review

Questions from firms and reviewers.

Where does Restoria run?

Restoria’s primary application infrastructure runs on Google Cloud in US regions. The Privacy Policy identifies the other providers used for authentication, structured data, AI processing, communications, and supporting services.

How is claim data encrypted?

Customer connections use HTTPS. Google Cloud encrypts customer content at rest by default, including data stored in Cloud Storage and Secret Manager.

Does Restoria train models on claim data?

Restoria does not use confidential claim data to train AI models without explicit customer consent.

Can a firm export or retain its records?

Yes. Customers receive a 30-day export window after termination and may request a read-only compliance hold for longer statutory retention needs.

How do I report a security concern?

Email [email protected] with the affected surface, steps to reproduce, potential impact, and a safe way to reach you. Do not include live customer claim data in the report.

Need a closer review?

Talk directly with Restoria security.

Send your security questionnaire, architecture question, or incident report to the team responsible for Restoria’s security program.

Email [email protected]

Security information last reviewed July 22, 2026.

Analytics and website-marketing technologies are enabled by default. Turn either category off below at any time. A Global Privacy Control signal automatically keeps both categories off.