Your records never train an AI model. Ever.
Not ours, not a vendor's, not "de-identified for research." Your files are processed to produce your outputs, and that is the end of their journey. This is contractual (it's in the BAA), not a settings toggle.
6 controls your reviewer will ask about.
TLS 1.2+ in transit, AES-256 at rest — every file, every environment.
HIPAA-minimal by default: people see only the cases assigned to them. Nothing else exists for them.
Every PHI access event is logged: who, what, when — and exportable for your own audits, appeals, and records requests.
Token-validated sessions with strict expiry handling. No shared credentials, anywhere.
Controls documentation and evidence packages maintained audit-ready, available under NDA.
Every output cited, reviewable, and traceable to its source. AI does the reading; your experts make the calls.
Deployment & integration
For carriers, TPAs, and public-sector programs deploying at scale.
Secure REST API and CRM token exchange, no shared credentials — with outbound webhooks into your case-management and claims systems.
Per-feature, per-file metering — bill costs back to a case, a client program, or a desk.
Retention controls, de-identified export for sharing without exposing PHI, and deletion on request.
Who touches your data, and what happens if something goes wrong.
Notice of any breach of unsecured PHI without unreasonable delay, and in no event later than 72 hours after we confirm it, as set out in the DPA and the BAA.
4 vendors, all under BAA, zero-retention, no-training: AWS (US-hosted infrastructure), Anthropic, OpenAI, and OpenRouter (model inference and routing). Full detail: Subprocessor List.
Customer Content is processed in the US only. At termination, PHI is returned within a 30-day export window, then destroyed (including backups) with a deletion certificate.