Security

Your patients’ paper, handled like it.

AiReq reads requisitions, insurance cards and identity documents. That is protected health information, and this page says exactly what happens to it — in enough detail that a compliance review can be finished rather than started.

A signed BAA

Before any real document moves. We are a business associate, and we sign an agreement that says so.

A person on every order

Nothing posts on its own. AiReq drafts; a member of your staff reviews and signs off before an order exists.

Named subprocessors

Listed below, by name, including the model that reads the page. No unnamed third parties touch your documents.

What happens to a document

A requisition arrives — uploaded in the product, posted to the API, or scanned to an address we issue you. It is read, and a draft order is produced with every value traceable to where on the page it came from. That draft sits in a queue until one of your technicians confirms it. Only then does an order exist. If you connect your own system through the API, that system decides when an order is created.

The draft is not a decision. A confidence score tells the technician how sure the model is about its own reading; it never gives the software authority to proceed without them.

Retention

What AiReq keeps, and for how long
What is keptFor how long
Extracted field values
Kept with the orderbecause that is the order
Audit trailWho confirmed what, and when
Life of the accountto answer questions months later

The extracted field values persist with the order, because that is the order. The audit trail — who confirmed what, and when — is kept for the life of the account, since it exists to answer questions months later.

We previously described this as “zero data retention” on another page. That was wrong and has been corrected: a duplicate check and an audit trail cannot function on data that was never kept, and we would rather be precise than reassuring.

Subprocessors

AiReq subprocessors
SubprocessorRoleWhat it touches
Google Gemini Extraction The model that reads the page
Amazon SES Inbound mail Documents scanned to an AiReq address
Langfuse Model monitoring What the model was given and what it returned, for each read

Extraction runs on Google Gemini. Documents scanned to an AiReq address arrive through Amazon SES. Each read is logged to Langfuse, so we can see what the model was given and what it returned. All three are covered by our agreements, and the current list is maintained here — changes are notified before they take effect.

Your documents are not used to train any model, ours or a third party’s, and no human at a subprocessor reviews them.

Scanning to an AiReq address

If you point an office scanner at us, each of your sites gets its own address with an unguessable component — so a mistyped address fails rather than delivering somewhere unexpected. Only senders you list are accepted; anything else is refused and logged with the reason, visible to you.

The same batch sent twice is recognised by its contents and collapsed, so a re-scan does not become a second set of orders. We keep a record that a message arrived — who from, when, its subject line, how many attachments, whether it was accepted — and not the body. Accepted attachments become documents in your queue, like any upload.

Certifications

AiReq is covered by CrelioHealth’s SOC 2 program, the same one that covers the CrelioHealth LIS. If your security review needs the report, ask for it with your questionnaire.

Asking us something this page does not answer

Send the questionnaire. A real person answers it, and if the honest answer is “not yet”, that is the answer you will get.