Security & data handling

Read-only to start.
Your data stays yours.

Claims data is regulated, personal, and yours. The deployment posture is built around that — starting read-only, on your terms, with every AI action on the record.

Watercolor illustration of a protected stack of claim files

01Data handling

What we read, where it lives, what we never keep.

NDA first

Every engagement — including the free audit — starts under NDA, before any file moves.

Read-only start

The audit step runs on a data export or read-only access. Nothing writes to your system until you approve automations — and then every write is approval-gated.

No-retention option

For the free audit, data handling is scoped to the engagement: findings delivered, source data deleted on request.

Demo data is synthetic

Everything on this site and in our demos uses illustrative, synthetic claims — labeled as such. Real data only ever moves under contract.

Access controls

Least-privilege access, scoped credentials per engagement, and audit logging on our side as well as the product's.

Compliance

SOC 2 program in progress; compliance documentation and subprocessor list available under NDA. We will never show a badge we haven't earned.

02AI governance

Every action, on the record.

  • Every AI action logged in the claim file with its reasoning
  • Sources cited on every finding — statutes, fee schedules, your SLAs
  • Your adjusters make every call; nothing consequential is auto-acted
  • Token and compute cost visible to the people who own the budget
  • Your playbook, encoded — carrier rules, not a vendor template

HELD FOR REVIEW — sources in the margin, ambiguity waits for a person, the adjuster signs. Illustrative document, synthetic data.

03Connection modes

Meets your system where it is.

API-first where an API exists; browser-level where one doesn't. Five connection modes from read-only export to approval-gated write-back — an integration program is never the precondition.

01 Scope
Least-privilege credentials
02 Observe
Read-only by default
03 Approve
A person gates every write
04 Record
Every action stays on the file
Unstructured documents become one typed, cited record without an API
No API required — unstructured files become one typed, cited record. Illustrative data

Diligence

Security questions? Ask them early.

We'd rather walk your IT and compliance teams through the posture before the pilot than after.

Prefer email? audit@hypermodel.ai