Your data never leaves your control. Our audits enter through a read-only tunnel.
Scrutexity doesn't install software, doesn't connect to PMS/EHR databases, and doesn't store PHI. Every audit is conducted through a read-only tunnel that captures only what is publicly visible — no server access, no database connections, no clinic-side integration.
No software install · No credentials needed · Zero downtime
Architecture Pillars
Four layers of safety, baked into every audit.
Read-Only by Design
Scrutexity scans public-facing web pages only. No server access, no database connections, no API integrations with clinical systems. Zero operational disruption.
BAA-Governed
Every audit is covered by a Business Associate Agreement. HIPAA-compliant data handling with full audit trail.
PHI-Redacted at Ingress
Phone numbers, email addresses, and patient identifiers are hashed per-clinic at the point of capture. Never stored in plaintext. Twilio ingress gateway strips PII before analysis.
SHA-256 Evidence Ledger
Every claim extraction is timestamped and sealed with a SHA-256 hash. Immutable proof of what was found, when, and in what state.
Comparison
Traditional audit vs. Scrutexity.
| Traditional Compliance Audit | Scrutexity | |
|---|---|---|
| Access | Full system access required | Public URLs only |
| Setup Time | 2–6 weeks | 2 minutes |
| Downtime | Yes | Zero |
| PHI Exposure | Full patient records | Redacted at ingress |
| Cost | $15,000–$50,000 | $497–$4,997 |
| Frequency | Quarterly / Annual | Continuous |
| Deliverable | Static PDF | Live claim ledger |
Trust Infrastructure
Six verifiable safeguards.
Every layer of the audit infrastructure is independently verifiable, documented, and governed by contract.
SOC2 Evidence Collection
via Vanta — continuous control monitoring and evidence export for your compliance team.
Twilio Ingress PHI Gateway
All inbound data passes through Twilio's infrastructure where PII is stripped before analysis.
BAA on request
A Business Associate Agreement is available on request for any engagement that may touch protected health information. We do not claim executed agreements we cannot show.
Read-Only Architecture
No database connections, no server agents, no PMS/EHR integration. Public web pages only.
SHA-256 Integrity Seals
Every extraction is timestamped and sealed. The ledger is independently verifiable.
No Data Retention Policy
We do not retain PHI. Redacted extracts are retained only for the audit lifecycle and purged on completion.
FAQ
Questions about the architecture.
Not sure if your site has claim drift? Run a free scan on AuditGPT — 30 seconds, no signup required.
Run a Free Claim Snapshot.
Enter your clinic URL. See exactly what claims your website is making — and what risks a regulator would flag. No signup, no software, no downtime.
Boundary: This is a non-clinical audit of marketing claims only. Results do not constitute legal advice, regulatory clearance, or FDA approval. Consult your compliance counsel before making material changes to your website.