Security
Security and data handling at Claimr
This page documents confirmed controls and the review process available to customers evaluating Claimr. Claimr is architected API-first, with server-side credential isolation and validated endpoints throughout — the same architecture this website's own sandbox and lead-capture endpoints run on.
- API-first architecture — every integration goes through validated, schema-checked endpoints
- Server-side credential isolation — API keys and MCP secrets never reach the browser
- Rate limiting and request validation on abuse-sensitive endpoints
- Request IDs on every API response for traceability
- Role-based access control for team and campaign management
- Data export and deletion controls