Security & compliance

Built for PHI from the first byte

ProofCustody is a deterministic audit system designed to handle protected health information safely from intake through export. This page summarizes our posture; our full security overview is available on request.

PHI redaction before export & AI calls

Personal and protected health information is redacted before it leaves the system — before any export is generated and before any call to an external AI service. Live-claim workflows are configured so original identifiers are not sent to external AI services.

Deterministic, no LLMs in the rules engine

Every finding comes from explicit, versioned rules — not a model guess. The same claim produces the same result, every time, which is what makes a finding defensible.

Row-level tenant isolation

Every record is scoped to a single client. Tenant isolation is enforced in the data layer and is under continued hardening ahead of general availability.

Tamper-evident audit trail

Each finding, decision, and reviewer action is written to a hash-chained, append-only trail capturing rule version, extraction version, reviewer identity, and timestamp.

Encryption in transit & at rest

Live-claim data is encrypted in transit and at rest in the configured HIPAA-eligible production environment.

BAA-ready for live claims

Ghost Audit sample reports run on synthetic sample data — no PHI, no upload, no agreement needed. Live-claim work runs under a Business Associate Agreement and a secure intake workflow.

Request the security pack

Our security overview and BAA template are available now; data-flow and subprocessor detail are shared as an evaluation progresses.

security@proofcustody.com

Compliance questions? compliance@proofcustody.com

Have a specific question? Contact us →