Data handling
Plainly, and without overstating it. Where something is not true yet, it is written here rather than left for you to assume.
A language model reads invoice documents. It never decides anything. Every verdict is produced by deterministic code with no model involvement, and every figure is cited to the page it came from — which is why a verdict can be reproduced and checked rather than trusted.
No model ever sees it. The Payment Integrity Review is arithmetic and set comparison performed entirely by our own code. Nothing from your export is sent to Anthropic or to any other external service.
You can delete all of it at any time, from the button at the foot of the payment history page. That removes every payment, finding, decision and the ledger the Verification Desk checks against.
The built-in sample invoice is different: its read was performed once by a real model and recorded, so demonstrating the product costs nothing and returns the same answer every time. The interface says which model read it and when. Anything you upload is read live.
The contents of an invoice document are sent to Anthropic's API to be read. We are not a "your data never leaves" product and will not claim to be. What is true: the read is under a no-training agreement, the document is purged after the verification, and your payment history never leaves at all — it is never sent anywhere.
We can truthfully say
We never say
We have tried to answer the questions a finance team should ask before they are asked. If one is missing, that is the most useful thing you can tell us.
Back to payment history