Security and data

What we do with what you send.

The free review takes no patient data at all. Four aggregate columns: payer, CARC code, count, billed amount. There is nothing in that to protect.

The review

We ask for

Aggregate rows

We never ask for

PHI

BAA required

No

Stored in

United States

If a file you send turns out to contain protected health information anyway, we tell you which column, delete it, and confirm the deletion in writing. We do not use it. The tool refuses the upload rather than quietly stripping it, because quietly stripping it would mean we held your patient data for a moment and told nobody.

Summaries are kept for twelve months unless you ask us to delete them sooner.

If you become a customer

Everything changes once real claims and charts are involved, and a Business Associate Agreement governs it.

A BAA with every vendor in the path

No tool touches PHI without one on file.

US infrastructure for patient data

Every system that touches patient data runs in a single United States region.

No consumer AI tools, anywhere

Zero data retention on every model API in the path.

A complete audit log

Every record read, every draft produced, every human action, every submission and its proof.

Nothing submits itself

No appeal reaches a payer without one of your people approving it.

SOC 2 Type II

Planned within twelve months of the first paying customer. Not yet held.

What is not true yet

We would rather tell you than have you find out.

Ask a security question One person reads that inbox.