Security & Trust

Your clients’ data, handled carefully.

Case files hold sensitive information about injured workers. Here is exactly how RateString protects it — in plain English, with no claims we can’t back up.

Encrypted in transit and at rest

All traffic runs over HTTPS/TLS. Saved cases are stored in an encrypted Postgres database (Supabase) with encryption at rest. Nothing is stored in plaintext on disk.

Your data is isolated from every other firm

Every saved case is protected by row-level security at the database layer — enforced on the server, not just in the app. You can only ever read your own cases (and, on a Firm plan, your own firm’s). No other account can query your data.

The free calculator never leaves your browser

On-screen ratings are computed entirely in your browser. The values you type into the unsaved calculator are not transmitted to or stored on our servers — only cases you explicitly save on a paid plan are stored.

We never see your card details

Payments are processed by Stripe, a PCI-DSS Level 1 provider. Card numbers go straight to Stripe and never touch our servers.

Analytics never record case data

We use privacy-respecting product analytics to improve the app, gated behind your consent. The calculator, workspace, and exhibit screens are masked — applicant names, claim numbers, and medical values are never captured in events or session recordings.

We don’t sell your data or train AI on it

Your case data is used solely to provide the Service to you. We do not sell personal information, share it for advertising, or use claimant data to train machine-learning models.

You control retention and deletion

You can export or delete saved cases at any time, and request deletion of your account. After closure we delete or de-identify your content within a commercially reasonable period, except where retention is legally required.

Built on trusted infrastructure

RateString runs on Cloudflare (edge, DNS, DDoS protection) and Supabase (managed Postgres + auth) — providers with mature security programs, least-privilege access controls, and monitoring.

We’re a young product and don’t yet hold formal certifications such as SOC 2 — we’d rather tell you what we actually do than imply audits we haven’t completed. As the firm grows, we’ll add independent attestations and publish them here.

A security question we didn’t answer?

Email [email protected] — we’ll get back within one business day. See also our Privacy Policy.