Security

How we protect your data.

You are handing us a medical bill and an insurance statement, some of the most sensitive documents you own. Here, in plain language, is how Verity handles them.

Encrypted in transit and at rest

Every connection to Verity runs over HTTPS (TLS), so your documents are encrypted the moment they leave your device. Once uploaded, files and records are stored on managed cloud infrastructure that encrypts data at rest. Your bill never travels or sits in the clear.

Your data is isolated to your account

Records are protected by database row-level security: a signed-in user can only ever read or write their own cases, documents, and results. This is enforced at the database itself, not just in application code, so one account can never reach another's data.

Uploaded files are stored under per-account paths and served only through short-lived, access-checked links, never as public URLs.

We minimize what the AI ever sees

Reading a bill requires showing it to a document-understanding model, but we treat identity as something to strip, not to send. Free-text you write (notes, a quoted phone call) is run through a de-identification step that removes names, account and member numbers, dates of birth, addresses, and contact details before anything crosses to the model. The extraction prompts are instructed never to copy your name, member ID, or address into their output, so identifiers do not propagate into stored results.

For the document-reading step itself, Verity supports running inference on infrastructure covered by a Business Associate Agreement (BAA), so that pathway can be operated without your documents egressing to a third party without that protection in place.

We never sell your data, and never use it to advertise

We do not sell your information, and we do not use your medical documents to target ads to you. Where we use information to test and improve our audit logic, we work to minimize and de-identify it first. You can opt out of that use by contacting us.

Payments are handled by Stripe

Verity does not store your card number. Payments run through Stripe, a PCI-DSS Level 1 certified processor, and card details are entered directly with them, never on our servers.

Retention and deletion, on your terms

You control your data. You can delete a case, and its uploaded files are removed along with it. Free scan reports created without an account expire automatically and are purged, including the underlying uploaded documents. When information is no longer needed for the purpose you gave it, it does not linger indefinitely.

Access is scoped and audited

Automated, privileged operations that must run outside a single user's session (for example, processing a payment confirmation) use tightly scoped service credentials that are never exposed to the browser. Sensitive keys stay server-side.

An honest note on what we are and aren't

Verity is a consumer medical-bill audit and dispute-preparation tool. We are not a covered entity under HIPAA, and we do not claim certifications we have not earned. What we can tell you plainly is how the system is built: encrypted transport and storage, database-enforced isolation, identity minimized before AI processing, no card storage, and deletion you control. If you have a security question this page doesn't answer, email support@verityclaims.co.

AboutPrivacyTermsHow it works