Security & data handling
Where your estimates go, and who never sees them.
If you have been pitched something in this category before, you have good reason to ask this question first. Here is the whole answer.
Insurers never see anything
We do not contact insurers, adjusters or third-party administrators about your claims. There is no submit button, no carrier integration and no adjuster-facing channel, and we will not add one. Your estimator prepares and submits every supplement themselves.
We do not sell estimate data, and we do not share it with carriers or claims data aggregators in any form.
Customer details are removed on receipt
Estimates carry personal information about your customers, who are not our users. Before a document is processed beyond initial extraction, we detect and remove:
- customer name, postal address and telephone number
- the vehicle identification number — only the last six characters are kept, hashed
- registration plate
- claim number and policy number
- adjuster name and contact details
- repair order number
The redaction is done on the extracted text and coordinates, not by drawing a black box over live text that can be copied out underneath.
Everything runs in the United States
Database and file storage run in AWS us-east-1. Application hosting runs in iad1, US East. Document extraction runs in a US region. Where a large language model is used — to draft the justification wording on a supplement, and to read estimates that defeat the column templates — it runs under US-only inference, and it is sent the redacted copy, never the original.
That last point is the one worth being precise about: the model is given an estimate with your customer stripped out of it. It does not receive names, addresses, VINs, plates, claim or policy numbers.
Who else touches it
Every vendor in the chain, what it can see, and where it runs, is listed in full on the subprocessors page. That list is the real one, not a summary.
How files are stored
Uploads go straight from your browser into private storage using a short-lived signed link. The bucket is not publicly addressable and has no public URL. Database access is constrained per-shop by row-level security, so one shop’s records are unreachable from another’s session. Keys with elevated access are held server-side only and are never sent to a browser.
No tracking on the upload page
There is no third-party analytics script and no session-replay tool anywhere on this site, and there never will be on the audit page — a replay tool would record the contents of an estimate as you attach it.
How long we keep it
- Unredacted originals — 90 days, then deleted.
- Redacted estimates and flag reports — while your account is active.
- Contributed samples — until you withdraw consent, under the contribution terms.
- Free-audit submissions that do not convert — 24 months.
Reporting a problem
Email security@suppsmith.com. We will not pursue good-faith researchers who follow the acceptable use policy.
Still want to test it before trusting it?
Send one estimate on a job that is already closed. You will see exactly what comes back and exactly what we did with the document.
Get my audit