Is my information secure?
Claim Raven uses layered safeguards for data in transit, VA connection tokens, browser sessions, and defined sensitive saved results, but no online service can promise zero risk. What is retained, encrypted, or sent to an AI provider depends on the feature you choose.
Overview
Claim Raven uses practical, layered security controls, but no online service can guarantee absolute security. You decide whether to connect VA data or provide records, and the current Security page and Privacy Policy explain what each feature collects, stores, sends to providers, and lets you remove. Security depends on the connection and feature A read-only VA connection, a VA Data Bridge import, an Ask Raven attachment, and a saved analysis do not have the same data flow or retention rule. Review the permission screen and the notice shown by the feature before you continue.
Security layers used today
Claim Raven uses different controls at different points. Each control has a boundary that matters. Area Current control Important boundary VA sign-in You authenticate on VA.gov through ID.me or Login.gov. Claim Raven uses OAuth 2.0 with PKCE and does not receive or store your VA.gov, ID.me, or Login.gov password. An approved connection returns OAuth tokens and only the VA data covered by the permissions shown to you. Read the VA authorization screen before approving access. Data in transit and browser sessions The application is configured to use HTTPS, send HSTS and other security headers in production, and keep session tokens in secure HTTP-only cookies. These controls do not protect a compromised device, a shared unlocked browser, a reused password, or information you send outside the intended product route. VA OAuth tokens The current VA connection flow encrypts new OAuth token writes using AES-256 before database storage and keeps access-token use on the server for authorized VA API requests. Disconnecting the VA app stops new VA profile information from reaching Claim Raven. It does not automatically delete a prior import, chat, report, analysis, or account. Defined sensitive saved results Selected sensitive saved outputs use application-managed authenticated encryption at rest, including saved Raven Eye analysis payloads and Raven Scan saved results. Do not assume every field, file, or feature uses the same storage format or retention period. The Privacy Policy describes the current rule by feature. AI processing AI features require consent. Submitted text, PDFs, images, screenshots, and relevant context may be sent to contracted AI providers to perform the feature you request. Masking is best-effort on supported text paths. Images and scanned-PDF pages may reach a provider before text-level masking is possible, and provider-side retention depends on current terms and configuration.
Source retention varies by tool
Check the current feature notice and Privacy Policy before providing sensitive material. This overview does not replace those specific disclosures. Feature Current source and result handling Available control Raven Eye Source files are processed in server memory and are not retained as saved source files after processing. A saved analysis can contain details extracted from the source and is encrypted at rest. Delete the saved analysis when you no longer want the derived result in your account. Ask Raven Original attachments and extracted text stay with the conversation so later turns and safe processing retries can use them. Remove an attachment, delete the conversation, use the Ask Raven Data controls in Settings, or request account deletion. Raven Scan Saved reports keep structured and derived findings encrypted at rest. Background-worker scans also retain an encrypted raw upload bundle with the linked job, and customer scan records are not scheduled for automatic purge. Use the saved-report deletion control. It deletes the validated bundle and scrubs linked customer and upload data before reporting success. Raven Cipher A C-File analysis retains the source PDF and derived record segments in protected storage so the analysis can be completed and reopened. Storage encryption depends on the current storage path and provider. Delete the analysis through its available control or use the verified account-deletion process when you no longer want the retained source and results. Other features Storage can range from memory-only processing to account-saved drafts, files, or results. Some tools use outside processors to deliver the requested feature. Read the feature notice and Privacy Policy, provide only what is needed, and use the feature's deletion control or the verified account-deletion process. Never send account secrets through support Do not send passwords, multifactor codes, recovery codes, Social Security numbers, VA file numbers, banking details, identity documents, or complete medical and claim records through an ordinary support email, contact form, or screenshot. Use a redacted example with only the technical details needed to show the problem.
Controls you can use
Review the VA authorization screen VA says a connected app can access only the information and permissions listed when you authorize it. Do not approve the connection if the list is broader than you expect. You understand the current permission request before any VA data is shared. Provide only what the feature needs Remove unnecessary identifiers before uploading when that will not prevent the feature from doing its job. Avoid putting credentials, unrelated records, or another person's information into a request. The feature receives the minimum useful information for the task you chose. Use feature-level removal controls Remove Ask Raven attachments or conversations and delete saved analyses or reports you no longer need. Check that the control confirms completion before treating the content as removed. Unneeded saved content is removed through the route that owns it. Control future AI processing AI features require consent. Use the available Settings control when you want to withdraw consent for future AI processing, and separately remove any saved attachments, conversations, reports, or analyses you no longer need. Future AI processing and previously saved artifacts are handled as separate choices. Treat VA disconnect and account deletion separately Disconnect through VA.gov when you want to stop new VA information from reaching Claim Raven. Follow the verified account-deletion process when you also want covered Claim Raven account data deleted. You apply the control that matches your intent instead of assuming one action does both.
What this answer does not promise
It does not promise that a breach, device compromise, provider incident, configuration error, or other security failure can never happen. It does not mean every item is encrypted by the same method or retained for the same period. It does not mean a read-only VA connection covers a file, chat, answer, or import you separately choose to provide. It does not mean disconnecting VA access deletes information already stored in Claim Raven. It does not mean Claim Raven is a VA service, is endorsed by VA, or represents you before VA.
Current privacy and security sources
Current privacy and security sources VA: Connected apps FAQs https://www.va.gov/resources/connected-apps-faqs/ Claim Raven Security and Privacy https://claimraven.com/security Claim Raven Privacy Policy https://claimraven.com/privacy-policy
Related privacy guidance
Related privacy guidance Keep private records and support requests safe /help-center/privacy-and-security/feature-data-protection See what Claim Raven can access /help-center/privacy-and-security/faq-what-can-claim-raven-access Disconnect Claim Raven from VA data /help-center/privacy-and-security/faq-revoke-access Delete your Claim Raven account and covered data /help-center/privacy-and-security/faq-delete-account Review the Claim Raven Security page /security Read the Claim Raven Privacy Policy /privacy-policy
More information
Review current security details Open the Security page for the current VA authentication, AI processing, retention, infrastructure, and user-control overview. Open Security and Privacy /security
Common questions
Is my information secure?
Claim Raven uses practical, layered security controls, but no online service can guarantee absolute security. You decide whether to connect VA data or provide records, and the current Security page and Privacy Policy explain what each feature collects, stores, sends to providers, and lets you remove.