Security

Security and data handling at Claimr

This page documents confirmed controls and the review process available to customers evaluating Claimr. Claimr is architected API-first, with server-side credential isolation and validated endpoints throughout — the same architecture this website's own sandbox and lead-capture endpoints run on.

  • API-first architecture — every integration goes through validated, schema-checked endpoints
  • Server-side credential isolation — API keys and MCP secrets never reach the browser
  • Rate limiting and request validation on abuse-sensitive endpoints
  • Request IDs on every API response for traceability
  • Role-based access control for team and campaign management
  • Data export and deletion controls