Security and compliance

Everything we can prove, and everything we cannot.

This page exists because the rest of the site would not be worth reading without it. The first half is what the product does; the second half is what it does not, with the reason.

What is in place

The evidence chain is recomputed, never trusted

The fingerprint of an item is calculated server side from the bytes actually stored. A fingerprint offered by the client is not accepted. Two writers racing for the same position lose gracefully: the loser re-reads the tail of the chain and tries again.

The seal refuses a broken chain

Sealing folds the fingerprints in order into a single root and records how many items it covers. If the chain does not verify, there is no seal — the state is reported, not repaired.

Portal links are stateless and revocable

The token is a signed payload; there is no session behind it. The role filter is applied inside the query. Releasing the assignment kills its links immediately, expiry or no expiry.

Certified mailbox passwords are encrypted at rest

Stored with authenticated encryption under a key held in the environment, and omitted from every read. Testing a mailbox performs a real connection and reports the outcome — a refused login is an answer, not an error.

The public bridge fails closed

Without its signing key every versioned route answers 503. It has its own rate limits per address and per company, its own upload ceiling, and it can only write to the intake queue.

The boundary is the company

Data is scoped by tenant, and each route names the permission it requires before it looks at the session. The claims and roadside modules carry independent permission catalogues.

European ground

Hosting, storage and processing stay in the European Union. The site mounts no analytics of its own and serves its own fonts: nothing in our markup asks anybody else’s network for anything. One caveat we would rather state than let you find: the delivery network in front of the site injects its own measurement script into every page. It is not ours and it is not governed from here.

Health data is treated as health data

An injury is a flag and a short description, minimised on purpose. It is not a clinical record, and it is not meant to become one.

What is missing

Read this part twice.

  1. 01

    The signature is a simple electronic signature

    Mandates, assignments and notices are signed at the simple level, with the surrounding evidence recorded — fingerprint, address, device, version of the notice. That is not an advanced or qualified signature. Because of that we do not, and will not, describe the accident statement form as compliant with the insurance regulator’s rules on digital forms. The data model already has the fields to move up a level once there is a qualified provider behind it.

  2. 02

    The qualified timestamp is optional, and off

    The seal can request a timestamp from a time-stamping authority and store the token verbatim so an outside verifier can check it. No authority is configured today, so the seal certifies the chain with its own root and nothing more. The file states the real outcome — there is no fabricated stamp.

  3. 03

    No automatic damage estimate from photographs

    This is a decision, not a gap. Estimating repair cost from an image is a fight against companies with years of appraised datasets. We would rather integrate one later than pretend to have one now.

  4. 04

    No manned operations desk

    The software receives, dispatches and pushes. It does not answer the telephone at three in the morning, and nothing on this site should be read as saying otherwise.

  5. 05

    Text messages and push need a provider

    The one-time code that lets the injured party in is delivered by email today, which works without any external supplier. Text messages and push notifications are wired to a generic provider that has to be configured before they leave the building.

  6. 06

    The assignment of receivables needs a lawyer

    Producing the document is easy. Its enforceability in motor liability is contested. Have it reviewed before it becomes part of how you sell.

  7. 07

    The professionals’ portal is English only

    The claim data is in the language it was entered in; the page around it is not translated yet.

Data protection

An impact assessment is owed, not advisable.

The processing involves photographs, location, identity documents and a description of injuries, at scale. That combination makes a data protection impact assessment mandatory, and it comes with the rest: a stated legal basis, granular and versioned consents, minimisation, retention periods, encryption at rest, a processing register and processor appointments towards every operator and partner in the chain. Consents are recorded on the claim and can be shown.

CONSENT RECORD ON THE CLAIMCONSENT RECORD ON THE CLAIM
CONSENT RECORD ON THE CLAIM

We can hand you what we hold — the model, the boundaries, the retention. The assessment itself is yours to run, because the processing is yours.

Bring us a real claim and we will run it end to end.

Half an hour is enough to see a claim opened from the app, the evidence sealed and the legal clock start ticking.