security
Your orders. Your rules. Your call.
Revenue Guard reads order data and payer policy. This page says what happens to both, in enough detail to finish a vendor questionnaire rather than start one.
Reads policy. Never touches claims.
It checks orders before billing. It does not submit, scrub or appeal anything, and it never talks to a payer on your behalf.
A named reviewer on every flagged order
Who decided, and when, against the exact version of the order they saw. Ignoring a flag requires a written reason.
Nothing runs until you promote it
A drafted rule is inert until someone on your team makes it live. One narrow exception is described below, in full.
The one thing that changes without you
Most corrections go to a person. One narrow class does not: when a change only narrows a rule — tightening which codes it catches — and a check against your own recent orders shows it fixes the flagged case and disturbs nothing else, it can apply itself.
It can never widen what a rule catches, and it can never create a rule. Those limits are enforced in code, not in a policy document. We put this near the top because it is the thing a careful reader would be annoyed to discover on page four.
Who can see what
Access is granted per person by an administrator at your lab. Every account has two isolated environments — live and sandbox — with separate data and separate API keys. A sandbox key cannot reach live data, which is deliberate and occasionally inconvenient.
The audit trail
Every state change is kept against the exact version of the order it was made on, so when a payer audits or a write-off is questioned six months later, the judgment is still there with a name on it. That record is kept for the life of the account, because that is what it is for.
Retention and subprocessors
Payer policy documents you upload are kept for 30 days and then deleted; the rules extracted from them persist, with the citation, because that is the product. Order data persists with the order.
Analysis runs on Google Gemini. Your orders and documents are not used to train any model, ours or a third party’s.
Sending us orders
Orders arrive over a single authenticated endpoint. Anything we send back to you is signed, and the signing secret can be rotated without downtime. Keys belong to one environment, so a test integration cannot reach production data by mistake.
What we do not have yet
Revenue Guard is not SOC 2 certified. If a certification is a hard requirement for your lab, say so early — we would rather be straight about timing than about status. Starting a trial does not depend on it; signing a contract might.
Questions this page does not answer
Send it over — a person answers it, and where the honest answer is “not yet”, that is the answer you get. You do not need to wait for that to start a trial; nothing real moves until you send us an order.