security
Your patients’ paper, handled like it.
AiReq reads requisitions, insurance cards and identity documents. That is protected health information, and this page says exactly what happens to it — in enough detail that a compliance review can be finished rather than started.
A signed BAA
Before any real document moves. We are a business associate, and we sign an agreement that says so.
A person on every order
Nothing posts on its own. AiReq drafts; a member of your staff reviews and signs off before an order exists.
Named subprocessors
Listed below, by name, including the model that reads the page. No unnamed third parties touch your documents.
What happens to a document
A requisition arrives — uploaded in the product, posted to the API, or scanned to an address we issue you. It is read, and a draft order is produced with every value traceable to where on the page it came from. That draft sits in a queue until one of your technicians confirms it. Only then does an order exist.
The draft is not a decision. A confidence score tells the technician how sure the model is about its own reading; it never gives the software authority to proceed without them.
Retention
Source documents are kept for 30 days and then deleted. The extracted field values persist with the order, because that is the order. The audit trail — who confirmed what, and when — is kept for the life of the account, since it exists to answer questions months later.
We previously described this as “zero data retention” on another page. That was wrong and has been corrected: a duplicate check and an audit trail cannot function on data that was never kept, and we would rather be precise than reassuring.
Subprocessors
Extraction runs on Google Gemini. Documents scanned to an AiReq address arrive through Amazon SES. Both are covered by our agreements, and the current list is maintained here — changes are notified before they take effect.
Your documents are not used to train any model, ours or a third party’s, and no human at a subprocessor reviews them.
Who can see what
Access to AiReq is granted per person by an administrator at your lab — being a member of the account is not enough on its own. Every account has two isolated environments, live and sandbox, with separate data and separate API keys; a sandbox key cannot reach live data, which is deliberate and occasionally inconvenient.
Scanning to an AiReq address
If you point an office scanner at us, each of your sites gets its own address with an unguessable component — so a mistyped address fails rather than delivering somewhere unexpected. Only senders you list are accepted; anything else is refused and logged with the reason, visible to you.
The same batch sent twice is recognised by its contents and collapsed, so a re-scan does not become a second set of orders. We keep a record that a message arrived — who from, when, how many attachments, whether it was accepted — and not the message itself.
Email is not an encrypted channel end to end. We require TLS on delivery to us and refuse connections that will not negotiate it, but a sending device you control may still be configured weakly. If that matters for your risk assessment, we will set you up with a folder-based upload instead — same product, no mailbox.
What we do not have yet
We are not SOC 2 certified today. We would rather say that here than let you find out in a questionnaire. If a certification is a requirement for your lab, tell us and we will be straight with you about timing rather than about status.
Asking us something this page does not answer
Send the questionnaire. A real person answers it, and if the honest answer is “not yet”, that is the answer you will get.