Security & compliance
Built for PHI from the first byte
ProofCustody is a deterministic audit system designed to handle protected health information safely from intake through export. This page summarizes our posture; our full security overview is available on request.
PHI redaction before export & AI calls
Personal and protected health information is redacted before it leaves the system — before any export is generated and before any call to an external AI service. Live-claim workflows are configured so original identifiers are not sent to external AI services.
Deterministic, no LLMs in the rules engine
Every finding comes from explicit, versioned rules — not a model guess. The same claim produces the same result, every time, which is what makes a finding defensible.
Row-level tenant isolation
Every record is scoped to a single client. Tenant isolation is enforced in the data layer and is under continued hardening ahead of general availability.
Tamper-evident audit trail
Each finding, decision, and reviewer action is written to a hash-chained, append-only trail capturing rule version, extraction version, reviewer identity, and timestamp.
Encryption in transit & at rest
Live-claim data is encrypted in transit and at rest in the configured HIPAA-eligible production environment.
BAA-ready for live claims
Ghost Audit sample reports run on synthetic sample data — no PHI, no upload, no agreement needed. Live-claim work runs under a Business Associate Agreement and a secure intake workflow.
Request the security pack
Our security overview and BAA template are available now; data-flow and subprocessor detail are shared as an evaluation progresses.
security@proofcustody.comCompliance questions? compliance@proofcustody.com
Have a specific question? Contact us →