← ClaimScope for Veterans

Service-provider register

ClaimScope will not enable real C-file intake until every provider that can receive Veteran information has an approved purpose, data scope, contract, retention treatment, and security review.

ProviderRolePlanned dataStatus
OpenAIModel-assisted document analysisC-file excerpts and generated analysisBlocked pending encryption, retention, data-use, and endpoint verification
DigitalOceanDedicated document-processing infrastructureEncrypted processing copies and operational metadataBlocked pending encryption, access-control, deletion, and production verification
Cloudflare / OpenAI SitesAuthentication, application hosting, database, and object storageAccount, matter, uploaded-file, and security-event dataPrivate launch only; production sensitive-data scope under review
StripePayment processingBilling identity and payment status only—never C-file contentsNo live product or price enabled
DocusignElectronic signaturesApproved engagement documents, VA appointment forms, signer identity, and audit trailDisabled until the firm account, templates, OAuth application, callback, and retention settings are approved
ResendTransactional noticesEmail address, delivery metadata, and non-sensitive portal notice text—never C-file attachmentsDisabled until the sending domain, scoped key, and webhook monitoring are approved

This register will be updated before production intake and when a provider or material data use changes.