Enterprise Security Built for Body Shops
Your shop handles sensitive customer data, financial information, and business intelligence. Claimory protects it all with role-based access control, row-level database security, and audit logging, so every team member sees exactly what they need and nothing more.
The Problem: Everyone Sees Everything, or Nothing
Most shop management systems have basic user accounts, but no real access control. Either everyone has full access (risky) or you can't share the system at all (useless). Body shops need granular permissions that match how different roles actually work.
Row-Level Security
Every database query is filtered to show only data the user is authorized to see.
Role-Based Access
Assign each team member a role that controls what they can see and do across the platform.
Audit Trail for Sensitive Actions
Claim changes and security events are logged with who, what, and when for accountability.
Workspace Isolation
Multi-location shops have complete data separation between workspaces.
Predefined Roles for Body Shop Operations
Claimory includes roles designed for how collision repair shops actually operate.
Owner
Full access to all features, settings, billing, and user management.
- View and manage all claims and cash jobs
- Access financial data and reports
- Manage team members and roles
- Configure workspace settings
- Manage billing and subscription
Manager
Day-to-day operational access with some administrative capabilities.
- View and manage all claims and cash jobs
- Access financial data and reports
- Assign work to team members
- Create and manage tasks
- Limited settings access
Estimator
Focused access for front office claim and estimate management.
- Create and manage claims
- View and edit estimates
- Communicate with carriers and customers
- Create tasks and notes
- Generate customer QR codes
Technician
Task-focused access for production floor work.
- View assigned claims and tasks
- Update task status and progress
- Log labor hours
- Add repair notes
- View relevant claim details
Security at Every Level
Claimory's security isn't just surface-level. It's built into the foundation of the platform.
Row-Level Database Security
Security policies are enforced at the database level, not just in the application. Even if someone bypasses the UI, they cannot access data they are not authorized to see.
Secure Authentication
Industry-standard authentication with secure password hashing and session management. Optional two-factor authentication (TOTP authenticator app) is available; enable it from Account settings.
Audit Logging for Sensitive Events
Claim creation, status changes and archives are recorded with the user and time, and a separate security log records role changes, API key changes and failed authentication. Useful for dispute resolution.
Rate Limiting and Bot Checks
Trial and invitation sign-ups, contact forms, shared file links, signing links and API keys are rate limited, and public sign-up and contact forms add a bot check.
Invitation-Only Access
New users can only join your workspace through an invitation from an existing admin. No unauthorized signups.
Encrypted Data Storage
All sensitive data is encrypted at rest and in transit using industry-standard encryption protocols.
Audit Trail for Accountability
Claimory records claim changes and security events with who did it and when.
Claim audit trail and security event log
Workspace Isolation for Multi-Location Shops
If you operate multiple locations, each workspace is completely isolated. Staff at one location cannot see data from another, unless your locations are grouped under one Enterprise account for the read-only cross-location roll-up.
Security Across All Features
Role-based security is enforced consistently across every part of Claimory.
Security FAQ
How does role-based security work in Claimory?
Claimory gives each team member a role: Org Admin for the owner, or Manager, Estimator or Technician. The owner decides, for each of the last three roles, eight permissions: view financials, edit financials, create claims, edit claims, delete claims, view reports, manage the team and manage settings. Postgres row-level security keeps every user inside their own shop's data, and removing a member from the workspace ends that member's access.
What are the key security capabilities in Claimory?
Claimory's security controls include Postgres row-level security for each shop, owner-editable role permissions, two-factor sign-in with an authenticator app, encrypted storage of connected Gmail and Outlook tokens, customer portal links that expire, records of claim creation, status changes and archiving with who and when, a security log of role changes and API key events, in-app account deletion and personal data export, and per-user read-only API keys on Professional and up.
How does Claimory security apply across its features?
Claimory role permissions decide who can open a claim's Financials tab, edit costs and payments, create, edit or delete claims, open reports, manage the team and change workspace settings. The shop calendar and the task list are visible to everyone in the workspace. A Claimory API key belongs to one user, reads only, and reaches only that user's shop.
Is role-based security included in Claimory's pricing?
Yes. Claimory role permissions, row-level security, two-factor sign-in and encrypted storage are on every plan, starting with Starter at $49.99 per month per location. Seats scale by plan: 1 on Starter, 3 on Professional and unlimited on Elite and Enterprise.
Can I customize roles and permissions for my shop in Claimory?
Yes. In Claimory's Roles and Permissions panel on the team page, the owner switches each of the eight permissions on or off for Manager, Estimator and Technician, and any permission left alone keeps Claimory's default. Role assignments and removals are recorded in Claimory's security log.
How does Claimory handle security for mobile access?
Claimory runs in a phone browser with the same role permissions, row-level security and two-factor sign-in as on a desktop, over an encrypted connection. Removing a member from the workspace ends their access on every device.
Can I review audit logs for my workspace in Claimory?
Not in the app today. Claimory records claim creation, status changes and archiving with who and when, and a security log of role changes, claim deletions and API key events, but a shop has no screen to browse them; the Tool Activity page does show every Claimory AI action run in the workspace. For a DRP review or a carrier audit, Claimory support can pull the records.
Is Claimory compliant with data protection regulations?
Claimory is built with data protection controls: row-level security per shop, role permissions, two-factor sign-in, encrypted connections and encrypted storage of connected-account tokens. Each user can delete their account or export their personal data from the Account page. For a specific requirement such as GDPR or CCPA, contact info@claimory.io.
Ready to Secure Your Shop's Data?
See how Claimory's role-based security can protect your customer data and give your team appropriate access.
No credit card. Works with CCC ONE and Mitchell.
