Security
How we protect your case files
Workers’ compensation files contain claim details and personal information about injured workers. Here is how MyWorkComp keeps that information safe.
Infrastructure
- MyWorkComp runs on Amazon Web Services in the United States (US East, Ohio).
- The application database runs in private network subnets and is not reachable from the public internet.
- Document storage buckets block all public access.
Encryption
- All traffic to the application is encrypted with TLS 1.2 or higher. Plain HTTP requests are redirected to HTTPS.
- The database, document storage, and backups are encrypted at rest.
- Credentials for connected systems, such as MerusCase, are encrypted before they are stored.
Access control
- Staff sign in with their existing Google or Microsoft work accounts, so your firm’s password and multi-factor policies apply.
- Each user is limited to the workspaces and actions their role allows. Firm administrators manage roles and membership.
Backups and logging
- The production database is backed up daily, and backups are kept for 14 days.
- Application logs are kept for 30 days to investigate errors and security events, then deleted.
Your data
- Customer documents are processed only to provide the service to the firm that uploaded them.
- Our subprocessors are not permitted to use your documents for their own purposes, including training their models.
- When a firm leaves, its data is deleted from active systems within 30 days and from backups within 60 days.
Report a security issue
If you believe you have found a security vulnerability in MyWorkComp, email sales@myworkcomp.ai with “Security report” in the subject line. Please give us a reasonable amount of time to fix the issue before sharing it publicly, and do not access or change data that is not yours.
Questions about how we handle personal information are covered in our Privacy Policy.