Prevent. Detect. Prove.
Three layers, one goal: every claim leaves a record that can stand up to a hostile expert.
1. Prevent: consent sealed at the point of care
Most billing disputes start with a missing record. Was the patient actually consented? Was the order active? By the time anyone asks, the moment is gone and the paperwork is a reconstruction.
We seal consent at the point of care, when it happens. The seal is cryptographic, so the record cannot be quietly rewritten later. The consent-seal method is the subject of a patent filed in 2026. That means the strongest evidence in a dispute exists before the dispute does.
2. Detect: deterministic contradiction rules
The engine runs 28 deterministic rules against each claim and the records around it: orders, consents, device registries, readings, encounter histories. Each rule looks for one thing: a typed contradiction between records that should agree.
Deterministic means the same inputs always produce the same output. Not patterns in a black box. Not a model score that shifts with retraining. Every finding cites the rule that fired and the exact records that contradict each other, so a reviewer can open those records and see it.
Of the 28 rules, 27 have measured precision on labeled synthetic ground truth, published in full on the methodology page, including the rules whose numbers are not good yet.
3. Prove: the hash-chained bundle
Findings are only useful if nobody can tamper with them. Every investigated claim produces a Claim Passport: six entries, each hashed into the next. The chain covers the claim, the findings, the methodology, the gap list, the reproducibility kit, and a public anchor. Change one byte anywhere and the chain breaks visibly.
The anchor is dual: an OpenTimestamps proof on the Bitcoin blockchain and an RFC-3161 token from a timestamp authority. Two independent public clocks attest that the bundle existed, unaltered, at a point in time. Nothing about the patient leaves the machine; only a hash is anchored.
Why a certificate and not a score
A fraud score asks a buyer to trust an unexplainable number. It names no specific record, so a provider can always argue with it. It cannot be defended in court, because there is nothing behind it to cross-examine except a model.
A forensic certificate documents one specific contradiction on one specific claim. It carries its own methodology, its own gap list, and a reproducibility kit. It carries a public timestamp. An opposing expert can re-run it byte for byte and get the same answer. That is the difference between an opinion and a record, and it changes what the artifact is worth the day a payer, an auditor, or a court asks questions.
The honest limits: the certificate does not judge medical necessity or the clinical accuracy of readings, and it says so in its own gap list. Precision figures are measured on synthetic ground truth. Field performance requires a calibration pilot on the customer's own data.