Scrutexity
Architecture · Safety-First Design

Your data never leaves your control. Our audits enter through a read-only tunnel.

Scrutexity doesn't install software, doesn't connect to PMS/EHR databases, and doesn't store PHI. Every audit is conducted through a read-only tunnel that captures only what is publicly visible — no server access, no database connections, no clinic-side integration.

Start a Free Claim Snapshot

No software install · No credentials needed · Zero downtime

Architecture Pillars

Four layers of safety, baked into every audit.

Read-Only by Design

Scrutexity scans public-facing web pages only. No server access, no database connections, no API integrations with clinical systems. Zero operational disruption.

BAA-Governed

Every audit is covered by a Business Associate Agreement. HIPAA-compliant data handling with full audit trail.

PHI-Redacted at Ingress

Phone numbers, email addresses, and patient identifiers are hashed per-clinic at the point of capture. Never stored in plaintext. Twilio ingress gateway strips PII before analysis.

SHA-256 Evidence Ledger

Every claim extraction is timestamped and sealed with a SHA-256 hash. Immutable proof of what was found, when, and in what state.

Comparison

Traditional audit vs. Scrutexity.

 Traditional Compliance AuditScrutexity
AccessFull system access requiredPublic URLs only
Setup Time2–6 weeks2 minutes
DowntimeYesZero
PHI ExposureFull patient recordsRedacted at ingress
Cost$15,000–$50,000$497–$4,997
FrequencyQuarterly / AnnualContinuous
DeliverableStatic PDFLive claim ledger

Trust Infrastructure

Six verifiable safeguards.

Every layer of the audit infrastructure is independently verifiable, documented, and governed by contract.

SOC2 Evidence Collection

via Vanta — continuous control monitoring and evidence export for your compliance team.

Twilio Ingress PHI Gateway

All inbound data passes through Twilio's infrastructure where PII is stripped before analysis.

BAA on request

A Business Associate Agreement is available on request for any engagement that may touch protected health information. We do not claim executed agreements we cannot show.

Read-Only Architecture

No database connections, no server agents, no PMS/EHR integration. Public web pages only.

SHA-256 Integrity Seals

Every extraction is timestamped and sealed. The ledger is independently verifiable.

No Data Retention Policy

We do not retain PHI. Redacted extracts are retained only for the audit lifecycle and purged on completion.

FAQ

Questions about the architecture.

Not sure if your site has claim drift? Run a free scan on AuditGPT — 30 seconds, no signup required.

Run a Free Claim Snapshot.

Enter your clinic URL. See exactly what claims your website is making — and what risks a regulator would flag. No signup, no software, no downtime.

Start a Free Claim Snapshot

Boundary: This is a non-clinical audit of marketing claims only. Results do not constitute legal advice, regulatory clearance, or FDA approval. Consult your compliance counsel before making material changes to your website.