Service-provider register
ClaimScope will not enable real C-file intake until every provider that can receive Veteran information has an approved purpose, data scope, contract, retention treatment, and security review.
| Provider | Role | Planned data | Status |
|---|---|---|---|
| OpenAI | Model-assisted document analysis | C-file excerpts and generated analysis | Blocked pending encryption, retention, data-use, and endpoint verification |
| DigitalOcean | Dedicated document-processing infrastructure | Encrypted processing copies and operational metadata | Blocked pending encryption, access-control, deletion, and production verification |
| Cloudflare / OpenAI Sites | Authentication, application hosting, database, and object storage | Account, matter, uploaded-file, and security-event data | Private launch only; production sensitive-data scope under review |
| Stripe | Payment processing | Billing identity and payment status only—never C-file contents | No live product or price enabled |
| Docusign | Electronic signatures | Approved engagement documents, VA appointment forms, signer identity, and audit trail | Disabled until the firm account, templates, OAuth application, callback, and retention settings are approved |
| Resend | Transactional notices | Email address, delivery metadata, and non-sensitive portal notice text—never C-file attachments | Disabled until the sending domain, scoped key, and webhook monitoring are approved |
This register will be updated before production intake and when a provider or material data use changes.