Security and compliance are architecture — not a trust badge.
We are building for regulated buyers. That means control and auditability are part of every agent's design, not a separate workstream bolted on at the end.
Protected health information, handled like it matters.
Agents handle PHI per HIPAA-aligned practices: data segregation, least-privilege access, encryption in transit and at rest, and detailed access logging. PHI is treated as a first-class data class with stricter controls than ordinary operational data.
Regulated outputs are human-reviewed before release.
Claim content, appeal language, applications — anything carrying regulatory exposure — is reviewed by a person before it leaves the system. This directly mitigates the most common AI failure mode in RCM: confident, plausible, wrong submissions.
We define HITL per agent, per output category, with explicit triggers (dollar threshold, confidence threshold, regulated category). It is configurable; it is auditable; it is never optional for high-exposure outputs.
Reviewable trails for compliance and internal audit.
Every agent action and decision is logged and retained — including the inputs, the rules applied, the model output, the human review state, and the final outbound result. Compliance and internal audit can reconstruct any case from first contact to disposition.
Confidence-based autonomy, monitored continuously.
Agents pass an evaluation suite before they go live, are monitored continuously in production, and operate at confidence-based autonomy levels with defined escalation paths. Drift tightens gates automatically.
Agents augment compliant processes. Full stop.
No uncontrolled autonomous submission of regulated outputs. Agents make the work tractable; they don't substitute for the judgment your compliance program requires.
Pursuing formal third-party assurance as part of our launch path.
RCM Kit operates under HIPAA-aligned controls today. Formal third-party security assurance is part of our launch path; we will publish details here when they are confirmed and verifiable. We will not list certifications we have not actually earned.
Confirm exact compliance-roadmap wording with stakeholder before launch. The above is the conservative, certification-free default.
Stop staffing your revenue cycle. Deploy it.
We're rolling out the suite agent by agent. The early-access cohort is small by design — early onboarding, priority on roadmap influence, and a direct line to the team building it.
- → Onboarding before general availability
- → Roadmap influence on which agents ship next
- → Direct access to the build team — no SDR layer