Security & compliance

Security for the claim file.

Restoria protects sensitive claim work with Google Cloud infrastructure, firm-scoped access, and controlled processing.

  • Primary infrastructure on Google Cloud
  • Firm-scoped application access
Layered claim folders protected by a bronze shield beside a mapped Google Cloud network.

How protection fits together

One control system across infrastructure and claim work.

Google protects the underlying cloud platform. Restoria configures and operates the application controls that determine who can reach each firm, project, file, and AI workflow.

  1. 01 Encrypted connection

    Customers reach Restoria through HTTPS-protected web and API endpoints.

  2. 02 Authenticated firm

    Every protected request is tied to an authenticated user and active firm.

  3. 03 Authorized claim context

    The API verifies firm, project, file, chat, and action permissions.

  4. 04 Controlled processing

    Claim context enters isolated, purpose-limited AI workflows for licensed review.

Google Cloud security

A hardened cloud foundation.

Restoria’s primary application infrastructure runs on Google Cloud in US regions. These platform protections are combined with Restoria’s application and organizational controls.

01 / Encryption

Protected at rest

Google Cloud encrypts customer content at rest using AES-256 by default. Core GCP storage and secrets use Google-managed encryption keys.

Google Cloud encryption documentation

02 / Transit

Protected while moving

Customer connections use HTTPS. Google protects customer data moving within its networks with authenticated encryption controls.

Google Cloud transit protections

03 / Compute

Isolated application runtime

Restoria’s API runs on Cloud Run, where Google applies hardware-backed and software sandboxing layers between workloads.

Cloud Run security design

04 / Storage

Private claim-file storage

Claim files are stored in a non-public Cloud Storage bucket. Uniform bucket-level access keeps object permissions under Google Cloud IAM.

Cloud Storage access controls

05 / Secrets

Managed application secrets

Production credentials are bound from Secret Manager to the runtime identity rather than committed to source or embedded in the browser application.

Secret Manager encryption

06 / Delivery

Short-lived deployment identity

The production deployment exchanges GitHub identity for short-lived Google Cloud credentials and proceeds only after the main quality gate succeeds.

Workload Identity Federation

Identity & tenant separation

Access follows the firm and the work.

The firm is Restoria’s tenant boundary. The API—not a hidden button or browser route—enforces who may see and change each resource.

Firm-scoped authorization
User-supplied firm identifiers are not trusted. Project-backed resources derive their firm from the authorized project.
Role-based administration
Owners manage firm identity, membership, billing, and destructive actions. Firm adjusters share operational claim work under defined permissions.
Private user context
Chats and personal integrations remain private to their owner even when related project files are shared within the firm.
Scoped sandbox credentials
Isolated processing environments receive short-lived credentials restricted to one authorized project directory, not a reusable Google service-account key.
Change attribution
Consequential claim-data changes retain the acting user and source context for review and accountability.

Analytics and website-marketing technologies are enabled by default. Turn either category off below at any time. A Global Privacy Control signal automatically keeps both categories off.