Veterans Benefits AI
Technical security details
For security reviewers and anyone who wants the detail. The plain version is in the Privacy Center. Nothing here is a certification.
Encryption at rest
- Uploaded files, the text copied from them, and the saved workspace data are encrypted by the application before they are written to disk, using AES-GCM authenticated encryption with a 256-bit key.
- In production the server refuses to start if the encryption key is missing or weak, and it refuses uploads if encryption is off.
- The key is held by the operator in the host's secret store, separate from the data. It is one key for the whole store, not a key you manage.
- Disk-level encryption by the hosting provider is not claimed here.
Encryption in transit
- The site is served over HTTPS only. Cloudflare and the hosting provider terminate TLS in front of the app.
- Responses send Strict-Transport-Security for one year, including subdomains.
- A Content Security Policy limits scripts to our own site and Cloudflare's script host, blocks framing, and blocks plugins.
How accounts are separated
- All accounts share one encrypted store on one server volume. There is no separate database per person.
- Every request checks the signed-in account, and every file or record lookup is limited to that account. A document id that belongs to someone else returns not found.
- This is separation inside the application, not separate infrastructure per customer. Whoever holds the encryption key can decrypt the whole store.
Sign-in, sessions, and passwords
- Sign in with email and password, Google, or Apple. We never ask for a VA.gov password.
- Passwords are stored only as salted scrypt hashes. New email accounts must open a confirmation link before they can use the workspace. Reset links work once, expire after 1 hour, and sign out every device.
- Sign-in replies never reveal whether an email has an account. Sign-in attempts are rate limited, and the limiter fails closed.
- Session cookies are signed, HttpOnly, Secure, and SameSite=Lax. Sessions end after 12 hours, or after 2 hours idle. Signing in issues a new session id.
How documents are read
- PDF text that is already in the file is copied out on our server with page numbers and page labels, and stored encrypted next to the file.
- In My Records, scanned or picture-only PDF pages and stored photos are read with the same on-server Tesseract OCR, up to 60 pages and 64 MB per file with a time budget per file. Words read this way are stored as OCR pages and every quote from them is marked "Read by OCR, check it". Pages past the limits are flagged as picture pages and are not read.
- Statement review also reads photos and scans with Tesseract OCR, running on our server. The English language data ships with the app and is loaded from disk, so no page image leaves the server. One OCR job runs at a time, with a time limit per page.
- Ask My Records and the Decision Letter Explainer match words against the stored text and published VA rules. They do not call a language model.
Outside services
- No outside AI or language-model service is called anywhere in the server. Our pre-release checks fail if a model library is added, and the OCR check fails if the server tries to reach the network.
- Outbound calls go only to: Resend (account emails and opt-in deadline reminders: recipient and message), Stripe (web checkout and billing), Apple (Sign in with Apple and App Store subscription checks), and Google (Sign in with Google).
- Railway hosts the server and its volume. Cloudflare is in front of the site. Browsers load fonts from Google Fonts.
- None of these services receive uploaded files or workspace data.
Logging and deletion
- An audit log records security events (sign-in, upload, delete, share, export) with opaque ids, a time, and an outcome. Emails, file names, and file contents are not written to it, and the log is encrypted like the rest of the store.
- Deleting a document removes the file and its saved text. Deleting an account removes the profile, files, saved text, and sessions for that account.
- Operator backups, when taken, are encrypted copies made with the same key.
- Product counts are first-party: a fixed list of event names (for example “homepage opened” or “first document uploaded”) kept as totals per day in an encrypted file. No account id, email, IP address, cookie, or page address is kept with them. Browser events are not sent when Do Not Track or Global Privacy Control is on, and test accounts are not counted.
What we don't claim
- No HIPAA, SOC 2, or FedRAMP certification is held or claimed.
- No independent penetration test has been completed. Reports go through the Security page.
- Not built yet: two-step sign-in codes, email sign-in links, a separate file storage service, and a network firewall rule in front of every server.