Enterprise-Grade Security

Your Data is Protected

We take security seriously. Sensitive claim data is protected with industry-leading security measures and compliance standards.

Secure Authentication

Each customer receives a unique settlement link, verified against their vehicle registration and postcode. No passwords, no shared access.

Tenant Isolation

Claim data is logically isolated per operator using row-level access controls. Handlers only see their organisation's cases.

Purge on Completion

Personal data is scrubbed automatically the moment a case completes. Any case still open after 30 days is anonymised and marked expired. Only an anonymised statistical skeleton remains.

PII Redacted Before AI

Names, vehicle registration, postcode, email, phone, NINO, driving licence and bank/card numbers are replaced with opaque placeholders before any AI call, and restored locally afterwards.

Full Audit Trail

Every customer interaction, decision, timestamp, and every automatic purge is recorded, providing a complete compliance record for every claim.

Role-Based Access Control

Granular permissions ensure team members only access what they need. Managers oversee their team's performance, while handlers focus on their assigned claims.

Manager & handler dashboards with tailored views

Security Features

  • Personal data purged automatically on case completion
  • Abandoned cases anonymised and expired at 30 days, with a 7-day warning
  • Hosted in the EEA (AWS Frankfurt), with row-level security isolating each operator's data
  • Encrypted data at rest and in transit
  • Personal identifiers replaced before AI processing, restored locally
  • Settlement links verified by reg and postcode, invalidated on purge
  • Operator data isolated by row-level access controls
  • AI provider does not retain data or train on it
  • Every purge logged with a timestamp and reason

The release gate

TotalSettle performs almost no AI processing by design, and that is now enforced by the build itself: an automated gate blocks any release that adds communication with an AI service, unless it is a written, approved exception recorded with its reason. Our three existing exceptions, the engineer report reader that prefills the total loss form and its supporting text extraction (both under no-training AI terms named in our client contracts), and an admin-only marketing voiceover tool that never touches case data, are each recorded with reason and approval. A release that adds an unapproved AI call cannot ship.

Documentation & Policies

Full transparency. Read our policies and technical documentation.

Security & Compliance Overview

Comprehensive compliance posture and certifications

Download PDF

AI Safety & Security Policy

AI governance, anti-hallucination controls, prompt security

Download PDF

How We Protect Your Data

Two-layer privacy architecture explained

Download PDF

AI Data Handling

What is and is not sent to the AI, what is retained, and how access is scoped

View page

Data & AI Summary

One-page overview for compliance and decision-makers

Download PDF

Plain English Guide

Jargon-free overview for non-technical users

Download PDF

Technical Overview

Architecture and technology stack for IT teams

Download PDF

Terms of Use

Platform terms and conditions

Download PDF

Download the Full Security Pack

Get our security and compliance PDFs in one go. Enter your details below for instant access.

We will not share your information. See our privacy policy.

Security & compliance FAQ