Security
Last updated: October 6, 2026
AIMS keeps each organization’s insurance records in a separate workspace registered in the tenant registry. This page describes controls in the product. It does not replace your organization’s own security policies or administrator duties.
Encryption in transit
Traffic between your devices and the website and API is encrypted in transit using HTTPS (TLS).
Separate workspaces
Each organization has its own workspace. A signed-in user sees only the workspace their organization has authorized. Through normal use of the application, users cannot open another organization’s workspace or its records. Administrators control membership and should remove access when someone leaves the organization.
Access within your organization
What each user can view or change depends on the roles and permissions administrators assign. Sensitive operations can require additional verification steps configured for your organization.
Documents and insurance records
Policies, claims files, and other uploads are stored for your workspace and are not published on a public web address. Viewing and downloading require a signed-in account with access to that record.
Audit and monitoring
User activity is logged to support accountability and security review. The service monitors for suspicious sign-in activity and can block suspicious IP addresses.
Sign-in
- Passwords are stored as a hash, not as plain text.
- Repeated failed sign-in or registration attempts can require a CAPTCHA.
- Unauthorized access attempts can be logged for review.
- Idle sign-in sessions can expire after a period of inactivity.
Mobile app
The mobile app uses the same authentication and workspace boundaries as the web application for your organization. Camera access is used only when you capture photos or documents in the app, not in the background.
What you control
Use a strong private password and do not share it. Administrators should remove users who no longer need access. Turn off camera or notification permissions in device settings if you do not want those features.
Contact
Questions about security: creatingaspectsllc@gmail.com