04

Trust, security and continuity

Trust is enforced in the workflow.

Security, privacy, evidence provenance and financial controls are application behavior, not certification claims. Reclaimr does not claim accreditations it has not obtained.

Customer evidence should be available only to the people and systems required to operate the case—and every consequential action should leave a record.
ACCESS / 01

Access

Verified accounts, MFA, server-side role checks, session revocation, tenant-scoped queries and step-up approval for high-risk actions.

  • Organization-scoped membership
  • Role-specific financial and evidence permissions
  • Audited administrator elevation
EVIDENCE / 02

Evidence

Private encrypted object storage, malware scanning, expiring downloads, source hashes, extracted-fact locations and correction history.

  • No public document URLs
  • Source-location provenance
  • Confirmed and overridden states retained
INTEGRITY / 03

Integrity

Append-only audit history, immutable signed agreements, versioned rules and dossiers, idempotent webhooks and decimal-safe money records.

  • Replay-safe provider events
  • Exact agreement and Rule Pack versions
  • Decimal-safe ledger records
CONTINUITY / 04

Continuity

Retrying jobs, dead-letter visibility, provider health, daily backups, scheduled restore tests and fail-closed stale-data behavior.

  • Provider health and freshness gates
  • Backup and isolated restore evidence
  • Stale regulatory data fails closed

From upload to retained record.

  1. Receive privatelyValidate file type, scan for malware and store outside public access.
  2. Extract with provenanceKeep the page, sheet or source location and confidence for every fact.
  3. Authorize each useCustomer, partner and internal permissions are checked on the server.
  4. Retain deliberatelyApply recorded policies and legal holds without rewriting required audit or financial history.
  5. Delete through workflowVerify authority, record the decision and preserve only what must lawfully remain.

Configured does not mean healthy.

Provider-backed capabilities distinguish configured, healthy, stale, failing, never probed and blocked states. Required capabilities fail closed when credentials, freshness or qualification evidence is missing.

Production readiness also depends on approved legal terms, checker-approved launch rules, verified backups, isolated restore evidence and live provider qualification.

Report a security concern

Send responsible disclosure details to security@sablestonepartners.com. Do not include customer documents or credentials in ordinary email.