Authentication
Powered by Firebase Authentication with email & password. Tokens are verified server-side on every API call. Session management follows industry best practices.
Your insurance toolkit — built for speed
Tell us your name so we can greet you properly
Help us tailor the experience for your agency
Enter the access code from your team admin to continue
Altech is built with enterprise-grade security at every layer. Your client data is protected from browser to cloud.
Powered by Firebase Authentication with email & password. Tokens are verified server-side on every API call. Session management follows industry best practices.
Multi-tenant Firestore rules enforce strict per-user data isolation. Each account can only read and write its own documents — no cross-tenant access is possible regardless of client-side code. A catch-all deny rule blocks all unspecified paths.
Sensitive local data is encrypted with AES-256-GCM via the Web Crypto API. Encryption keys are derived using PBKDF2 with SHA-256 and a per-device salt. All cloud communication uses TLS 1.3 with HSTS enforcement.
Every API endpoint is wrapped in security middleware with per-user rate limiting, CORS origin whitelisting, and request ID correlation for end-to-end tracing. Authenticated users receive higher rate limits while anonymous requests are throttled.
All user inputs are sanitized server-side to prevent XSS and injection attacks. Dedicated validators verify email, phone, SSN, and ZIP formats. Field injection is blocked at the Firestore rules layer with explicit allowlists.
Path traversal attacks are blocked. Dotfiles, hidden directories, and sensitive paths return 403. Payloads are size-limited to prevent abuse. Static files are served with no-cache headers.
Client data is stored locally in your browser and syncs to your private cloud namespace when signed in. No data is shared between accounts. Exported files (CMSMTF, XML, PDF) are generated client-side and never pass through our servers. You can delete all cloud data at any time from Settings.
Questions about security? Contact us
Sign in to sync your data across devices
Get started with cloud sync for your team
Enter your email and we'll send you a reset link
Estimates assume typical usage. Actual costs vary with document length, image count, and response complexity.
Gemini 2.5 Flash is used by default. Add your own key for any provider to use premium models.
One term per line. The HawkSoft Logger AI will use these to interpret your shorthand notes. Max 500 characters.