Scope and current status
The marketing website and the ProofsCheck application are different systems. This public site explains the intended review workflow, but it does not include the comparison engine, customer accounts, document storage or customer records.
Current evaluation boundary: Use non-PHI demonstration material only. Do not submit confidential documents, patient-identifiable information or protected health information through the public website or initial enquiry.
Public website
The current public website is delivered as static pages with a server-side enquiry endpoint through Vercel. That fact describes website hosting only; it does not identify or attest to the application’s document-hosting environment.
- The website has no document-upload control, customer sign-in or application database.
- The site code does not include advertising pixels, behavioural analytics or a tag manager.
- The site code does not set analytics or advertising cookies, so no consent banner is shown.
- The demo form posts the entered fields to a same-origin server-side endpoint. That endpoint is designed to use Resend after email delivery is enabled; until then it returns an unavailable message without sending the enquiry to the inbox. The destination address and delivery credential are not included in browser code.
- The host and network providers involved in serving the page may process technical request data such as IP address, headers, timestamps and security logs under their own terms.
Application documents and supervised evaluations
ProofsCheck is intended to compare an approved reference with a proof, artwork file, form or captured printed sample. Because this repository does not establish the application’s technical controls, the following matters must be confirmed for the actual workflow before customer material is provided:
- which people can access the account, documents, findings and review records;
- the application host, processing providers, data locations and relevant subprocessors;
- approved document types and whether the material is confidential or regulated;
- retention periods for source files, derived evidence, results, logs and backups;
- the deletion-request process, identity checks, exceptions and backup expiry; and
- the support or human-review access required for the scoped evaluation.
No provider certification or attestation should be read as a certification of ProofsCheck or of a customer’s workflow. The exact service, credential and scope must be verified before any such claim is made.
Current handling summary
| Document intake | The public website does not accept uploads. Initial demos and evaluations must use non-PHI material provided through the agreed supervised process. |
|---|---|
| Access | There is no public application or customer-document access route in this website. Authorized-user and support-access rules must be confirmed in the pilot scope before sharing documents. |
| Hosting & processors | Vercel serves the public website and enquiry endpoint. Resend is selected for enquiry-email delivery but is not yet enabled. Application hosting, model or document-processing providers are not stated here because their exact service and scope have not been verified for publication. |
| Retention | The public website does not write form fields to a site database. The hosting, email-delivery and recipient-email providers may retain message or delivery data under the applicable configuration and terms. Application files, results, review history, logs and backups require documented retention criteria in the applicable pilot or customer terms. |
| Deletion | ProofsCheck does not publish an immediate or universal deletion guarantee. A scoped process must cover active data, derived files, audit records, legal exceptions and backup expiry. |
| Human review | Comparison findings are evidence for a reviewer. The responsible person verifies the result and makes the approval, correction or release decision under the organization’s procedure. |
Human review remains part of the control
ProofsCheck is not presented as an autonomous approval system or a guarantee that every difference will be found. Document complexity, rendering, image capture and the defined comparison scope can affect results.
A responsible reviewer should inspect the side-by-side evidence, resolve the finding under the organization’s procedure and record the final decision. A product output does not replace legal, regulatory, medical or quality-system judgment.
HIPAA readiness in progress
Our team plans to undertake HIPAA training and prepare the policies, safeguards and infrastructure needed to support HIPAA-compliant use in approved workflows.
PHI support is not currently available. Before enabling it, we will complete the required readiness work, validate the intended workflow and put applicable Business Associate Agreements (BAAs) in place.
Current demos and evaluations use non-PHI documents. Do not upload protected health information.
Training alone would not establish product compliance. HIPAA readiness also depends on risk analysis, policies, administrative, physical and technical safeguards, appropriate provider arrangements, incident procedures and workflow-specific validation.
Questions about an intended workflow
Use the demo enquiry for high-level business context only. Do not attach or paste documents, credentials, patient data, confidential production details or security-sensitive information into an initial enquiry.