Separate public and private spaces
This public website collects business inquiries only. The private workspace and inquiry inbox use Cloudflare Access with an owner allowlist and required additional authentication. Please keep patient information out of the inquiry form and ordinary email.
What is implemented
The application checks signed identity tokens, clinic roles and tenant access. Working state and retained originals use application encryption; private originals are stored in R2. Signed activity, version checks, source references and scoped exports support review and accountability. New retained uploads pass a private antivirus service. Daily encrypted backups and hourly audit copies use separate deletion-locked storage in the same Cloudflare account.
AI assists; rules decide
Extraction drafts and mapping hints must be reviewed against source evidence. AI does not determine coverage, eligibility, claim correctness or recoverable money. The deployed workspace remains restricted to fictional data while production controls and customer inputs are qualified.
Before a patient-data pilot
Private upload scanning and a populated fictional restore are implemented and tested. Hosting and processing agreements, independent security review, customer-volume recovery, customer-specific mappings and payer/product acceptance must still be completed. A configured control or a passing fictional test is not a certification.
Questions or a security report
Email hello@dosethread.com with a brief description and a way to reach you. Do not include patient records, passwords or exploitable details in the first message. We will arrange an appropriate channel.