Home › Security
Security & data handling
Interstate Medicine Ledger · Last updated: September 26, 2026
The Ledger holds a clinician’s licensing and credentialing record. This page says, in plain terms, where that record lives, who can see it, and what we do and do not claim. When something here changes, we change this page.
What we hold, and what we don’t
We hold a clinician’s own professional record: licenses and renewal dates, DEA and state controlled-substance registrations, board certifications, life-support cards, malpractice coverage, work history, CME certificates, the clinician’s own immunization and TB records if they add them, and the documents behind each of these. Date of birth and a photo ID are optional.
We do not hold patient records. Nothing in the Ledger is protected health information about patients. We do not accept or store Social Security numbers: the document reader is told never to read one, and any nine-digit number shaped like one is removed from its answer before it reaches your screen.
Where it lives
- Database and files: Supabase (Postgres and file storage), in its US East region. Netlify serves the web app and this site.
- In transit: every connection uses TLS. Browsers are told to use HTTPS only (HSTS).
- At rest: data and files are encrypted at rest by our hosting providers.
Who can see what
Every table in the database has row-level security switched on, and new tables get it automatically. The database itself, not the app, decides what each signed-in person can read.
- A clinician sees only their own record.
- An organization (an agency, telehealth group or practice) sees a clinician only after that clinician approves it, and only at the level the clinician picks. The clinician can lower or revoke access at any time.
- Every grant, change and revocation, every change an organization or helper makes, and every attempt blocked for too low a level is written to the clinician’s own activity log. When an organization views a clinician’s roster entry or credential expiry dates, that is logged there too. The clinician can download that log.
- Signed attestations: when a clinician signs the attestation and release, an organization with access sees that it was signed and when. It never sees the clinician’s answers to the disclosure questions.
- Organization API keys are read-only. We store only a SHA-256 hash of each key; the key itself is shown once, when it is created, and can be revoked at any time.
| Level | What the organization can do |
|---|---|
| 1 · Compliance only | See licenses held, requirements met or owed, and renewal dates. No identifiers. |
| 2 · Full profile | Level 1, plus license numbers, contact details, date of birth and the stored documents. |
| 3 · Manage | Level 2, plus uploading documents and correcting records on the clinician’s behalf. |
| 4 · Full control | Level 3, plus creating the account and handing it to the clinician’s email. |
Signing in
- New passwords are checked against known breached passwords. Only the first five characters of the password’s hash leave your device for this check.
- Two-factor sign-in with an authenticator app (TOTP) is available to every account. Once it is on, the code is asked for at every sign-in.
- Photo-ID documents can only be opened from a session that has passed the two-factor check. The file store and the database both enforce this.
- Changing your password or email, turning off two-factor, and deleting the account all ask for your password again.
How documents are read
- A document you add is first processed on your own device: its text is pulled out, or read with on-device OCR, and images are compressed.
- That text and an image of the first page then go to our AI reader, which runs on Anthropic’s API. It identifies the document and suggests the fields. Anthropic does not use API traffic to train its models. The reader is sent only what the document itself shows, never your account details.
- Each reading is stored by the file’s fingerprint (a SHA-256 hash), so adding the same file twice doesn’t send it again. These stored readings are deleted after 90 days.
- Nothing is added to your record until you review it and confirm. If the AI reader is unavailable, the on-device reading is shown instead and labeled as such.
Email and payments
- We send email through Resend. Documents emailed to your private upload address are accepted only from senders you have approved, and only when the sender’s domain passes SPF or DKIM. Anything else is held for your review.
- Payments go through Stripe’s hosted checkout. We never see or store card numbers.
Keeping and deleting data
- Your copy, any time: download a ZIP of your whole record, with spreadsheets and the original files.
- Delete your account, any time, from Settings. Your uploaded files are removed from file storage first, then your account and your record are removed from our database. If a file cannot be removed, the account is not deleted and you are asked to try again, so nothing is left behind.
- Set retention: stored AI readings are kept for 90 days. Emailed-in items are kept for 180 days once filed or dismissed, and 30 days if they never matched an account. Your activity log is kept for up to six years while your account exists.
Exclusion and registry checks
Once a month we compare each clinician’s name and NPI with public lists: the OIG exclusion list (LEIE), the CMS opt-out and Order & Referring files, and the NPPES registry. We download those lists and do the comparison ourselves, so your details are not sent to anyone for this. An organization can also run a SAM.gov exclusion check, which sends the clinician’s name to SAM.gov’s public search. Results are shown to the clinician, and to an organization only if the clinician has given it access; a match made on the NPI is shown to an organization only at level 2 or above. A name match is shown as a possible match for a person to review, never as a finding on its own.
Browser protections
The app sends HSTS, a Permissions-Policy that turns off camera, microphone, location, payment and similar browser features, and a rule that stops other sites from framing it. Our Content Security Policy currently runs in report-only mode. We collect its reports and will switch it to enforcing once they are clean.
What we do not claim
- No SOC 2 report and no HITRUST certification. Our hosting providers hold their own attestations; Interstate Medicine does not.
- No HIPAA business associate agreement, because we do not handle patient health information.
- No primary-source verification. We are not a credentials verification organization (CVO). The Ledger organizes what the clinician holds. Boards, facilities and payers still do their own verification.
Report a security issue
If you think you have found a vulnerability, email hello@interstatemedicine.com with “Security” in the subject. Please give us a reasonable chance to fix it before you share it. See also our Privacy Policy.