For government and contractors
Claim evidence analysis in isolated GovCloud
Veteran medical records stay in isolated AWS GovCloud, accessible only to authorized representatives, with a 90-day data retention period.
Deployment model
Isolated storage. Authorized access.
Isolated AWS GovCloud
Your medical records stay in an isolated AWS GovCloud environment. We do not download medical-record personally identifiable information (PII) to staff devices or copy it into public website systems.
Restricted access and defined retention
Only authorized representatives can access your medical records. Each medical record is retained for 90 days from when it is first received, then deleted.
Auditable by construction
Analyses record the engine, policy and registry versions that produced them, so a result can be traced to the exact rules in force at the time.
Control mapping
Requirements, and the mechanism behind each
A control mapping is a mapping. It is not a certification, and we do not claim one.
| Control area | Mechanism |
|---|---|
| Encryption | At rest and in transit. |
| Network isolation | Private subnets; no public path to the backend. |
| Access | Authorized representatives only, with least-privilege roles. |
| Audit | Append-only action logging. |
| Residency and retention | Isolated AWS GovCloud; deletion 90 days after each record is first received. |
| Evidence integrity | Signed artifacts. |
The planned redaction and tokenization layer is designed to mask identifiers before analysis and search indexing. Its requirements and planned status are described on the security page.
Read this first
Our posture, stated precisely
If you evaluate vendors for a living, this is the section that tells you whether the rest of the page is trustworthy.
FedRAMP-aligned, pursuing authorization
The platform is architected and operated to FedRAMP Moderate baseline controls, with FedRAMP High alignment on the security-critical subsystems. Authorization is something a deployment earns with an assessor, and we support that process rather than assert its outcome.
Control mapping to HIPAA requirements
PHI is handled under the minimum-necessary principle, with the redaction layer keeping identifiers out of the analysis entirely. Compliance is a property of a deployment and its operator; we map to the requirements and document every mechanism.
FIPS-ready packaging
Cryptographic packaging is FIPS-ready, running on FIPS-validated modules available in AWS GovCloud.
Corpus-measured, not corpus-inflated
Performance is measured against our reference corpus and we publish the method alongside the figures. Real-world accuracy requires labeled real documents and outcome comparison, so we do not quote a headline accuracy percentage we could not defend under audit.
On certifications
A FedRAMP Moderate authorization package is in preparation, and a SOC 2 Type II audit is targeted to follow it and leverage shared evidence. When each is granted, this page will name the issuing body and the date.
Until then we describe the control mapping and the mechanisms behind it, which is the claim we can put our name to in front of an assessor.
Next step
Bring your assessor's questions
We would rather answer the hard ones early than discover them during an assessment.