Security & data handling
ClaimLasso asks for sensitive visibility, so the rules have to be strict and easy to check. Here is exactly what we do — and what we will never do.
Read-only by design
Connections grant reading rights only. ClaimLasso has no payment capability and cannot place orders, transfer funds or change your account settings.
Encryption in transit and at rest (intended)
The live product is intended to encrypt data in transit and at rest. Nothing here is proof of an implemented control: this demo connects no real sources and stores no sensitive financial or email data.
Data minimization
We extract only the fields a claim needs — merchant, date, amount, order reference, policy match — and discard unrelated message content.
Revocable access
Disconnect any source at any time. Revocation takes effect immediately and future scans stop using that source.
Approval before contact
No merchant, bank or third party is contacted without you reading the message and explicitly approving it for that claim.
Deletion on request
Request deletion from Settings and we remove findings and evidence. Records we must keep for accounting are limited and documented.
What ClaimLasso never does
- Move, hold or spend your money
- Contact a merchant without your per-claim approval
- Sell or share your data with advertisers
- Read sources you have not connected
- Promise a guaranteed refund or savings amount
Current MVP status
This build is a clickable demo. No email, bank or payment provider is connected, all data is fictional, and the send action is simulated. Live integrations will only be enabled with per-source consent and documented scopes.
Read the privacy notice