Trust & Security | Last Updated: June 2026

Trust & Security

AuditGPT reviews the public, buyer-facing pages you point it at. It does not connect to your internal systems, your booking software, or any patient data. Here is exactly what we access, what we store, and what we don’t — in plain English.

01

What AuditGPT accesses

  • Public web content onlyYou give us a URL; we read the public page a visitor would see. We do not request logins, API tokens, or access to any internal system.
  • No patient data, no PMSAuditGPT reviews marketing and claim copy — not patient records, EMRs, or booking systems. We never ask for PHI.
  • Read-onlyWe read public pages. AuditGPT cannot change anything on your site or in your systems.
02

How we handle data

  • Zero-retention model inferencePage content is processed by our LLM provider (Anthropic) under non-training, zero-retention API terms. Your content is not used to train external models.
  • What we storeThe URL you submit and the resulting report. Exportable, and deletable on request.
  • EncryptionTLS 1.3 in transit; encrypted at rest (AES-256) on our hosting.
03

Subprocessors

We keep third parties to the minimum needed to run an audit.

EntityFunctionData Scope
AnthropicLLM inference (claim analysis)Public page content. Non-training, zero-retention API terms.
VercelApplication hostingEncrypted application state and routing.
04

What we don’t claim

Do you hold SOC2 or HIPAA certification?
Not yet, and we don’t claim to. AuditGPT is a founder-led tool that reviews public web pages; access to our systems is limited to the founder and a designated operator. We say so plainly rather than imply controls we haven’t completed.
Do you touch our PMS, booking system, or patient data?
No. AuditGPT reads public marketing pages only. There is no integration with Boulevard, Mangomint, an EMR, or any patient-facing system.
Do you sell or share our data?
No. We don’t sell or share your data, and we don’t use third-party ad pixels to track you.

Security & IT inquiries

We’ll answer questions about access, storage, and deletion before you commit to anything.

security@scrutexity.com