Security
Built for high-stakes environments — stated precisely
Precision builds credibility with federal buyers. Alignment language is not certification.
Precision builds credibility with federal buyers. We do not describe alignment as certification.
Controls
What we will say in public — and what we will not
Zero trust
Architecture assumes no implicit trust inside the perimeter. Access is verified, limited, and logged.
Encryption
In transit and at rest. Public educational flows do not require document upload.
Immutable audit logging
Assisted outputs are designed to be reconstructable. Black-box scoring is not the public product.
Human override
Authorized humans reject or revise assisted output. Official determinations remain with the VA, accredited representatives, and clinicians.
PHI boundary on this website
Do not submit medical files, DD-214s, or SSNs on the public site. The Claim Readiness Assessment does not require records upload.
Regulated-environment design
Azure Government–ready foundation. FedRAMP Moderate alignment in progress. HIPAA-ready controls as architecture — not covered-entity certification, not an ATO.
Stated precisely
- Zero-trust architecture
- HIPAA-ready controls and encryption — readiness, not a claim of current HIPAA covered-entity certification
- FedRAMP Moderate alignment in progress — not an authorization to operate
- Designed for Azure Government — not a statement that production is already authorized there
- Immutable audit logging
- Tribal sovereignty protections
- Full explainability with human oversight
How the system is built
Tanner Tobey, CISSP, engineers the system to the standard expected in high-stakes environments. Leigh Ann’s process is what the software executes. The veteran outcome is the purpose.
- Modern frontend and backend architecture
- Azure Government–ready foundation
- Container orchestration and secure deployment practices
- Sovereign AI capabilities with human override
- FHIR R4 health data interoperability