Consistency privacy and billing
See how Consistency handles your documents and what a packet costs.
Consistency reads a packet to compare its documents, then returns places to check. This page explains how it handles those documents and what a run costs.
flowchart LR
A["Packet in<br/>documents and known facts"] --> B["Compare<br/>documents and facts"] --> C["Plain answer<br/>what may disagree"] --> D["Proof<br/>where to check"]Documents and history
Files are uploaded to our service for analysis. History is off in this playground, so later packets are not compared with this one. Sealed replay evidence can retain coded document data. It does not retain readable document text. A delivered packet costs 6 SCU per page. A problem in the answer points to evidence for a person to check.
For claims reviewers
Use synthetic documents in Preview. Before a run can open a document, the organization must state whether it is a HIPAA covered entity or business associate. A covered entity or business associate also needs the BAA flag. If the gate refuses a request, the service does not bill it.
Consistency costs 6 SCU per page. An image document counts as one page. For example, a three-page PDF and two photos cost 30 SCU for a delivered packet. A retry of the same request and a job status check cost nothing.
Technical details
What The Engine Sees
The sectioner reads each document once. It extracts the text (OCR for scanned pages), cuts it into sections, and masks names, identifiers, and dates.
The gateway then turns every token, every ref you sent, and every date into a keyed hash (HMAC) before the engine runs. The engine compares these codes. It never reads the text of a document or a ref in the clear. A keyed hash is one-way. The code cannot be turned back into the word.
In Preview the comparison key is new for every request and is erased after matching. Two requests never share a key, so codes from one packet cannot be matched against another.
Findings, match records, and evidence packages store keyed tokens, positions, and hashes. None of them store readable document text. The only copy of your files is the encrypted packet an async job holds until it expires (see below). The Playground itself keeps only hashes and status codes for each run, never the document bytes or the response.
Document ids, claim refs, and line ids are the exception. They come back in the response as you sent them, so keep patient data out of them.
Which Models Read Your Documents
Every model that reads a customer document runs inside our cluster. The sectioner, its OCR, and the document-type readers run in the vision service. No page, text, or embedding goes to a third-party API.
A model served outside the cluster may read synthetic or evaluation documents only. An in-cluster model service must be on an allow-list of cluster hosts before it can receive customer text, and that path stays off until a separate data-handling review turns it on. A model's answer is cached as labels and option ids, never as the model's free text.
Organizations Stay Apart
- The engine compares documents inside one packet only. Preview keeps no memory of earlier packets, so one organization's documents are never compared with another's.
- Job records are read under the caller's organization. The database's row-level security confines every poll to the caller's own jobs. Another organization's job id returns
404. - Stored payloads and results are encrypted with AES-256-GCM. Each ciphertext is bound to its purpose and to its storage name, which includes your organization id. A payload cannot be served as a result or under another organization's name.
- An accepted packet and its result expire 24 hours after the job ends, and after 7 days at most if it never ends.
Planned: a per-organization memory, so a new packet is judged against that organization's history. Each organization will get its own keys, so the same sentence makes a different code for each one. Cross-organization matching will need an explicit, audited grant.
Sealed Evidence And Replay
Every decision is written to an evidence package: the keyed inputs, the rule flags, the pack hash, the engine versions, and the verified matches. The package holds keyed streams, positions, and hashes only. It holds no readable text.
The package is sealed with AES-256-GCM. evidence_package_ref in the response names it. Server-side replay re-runs the package from its sealed bytes and must produce byte-identical findings.
In Preview the sealing key and the comparison key live in the gateway process only. The process keeps the latest 256 packages for replay and drops older ones. Packages are not downloadable.
Planned: packages kept in encrypted storage under the organization's key, and a signed export that holds your side of each finding and never the matched document's token stream.
Covered Entities And The BAA Gate
Every consistency path that opens a document passes the same admission gate before anything is accepted. The playground passes it too.
| Your organization | What happens |
|---|---|
| Has not stated its regulated-entity status | 403 attestation_required |
| Is a HIPAA covered entity or business associate, BAA flag not set | 403 baa_required |
| Is a covered entity or business associate, BAA flag set by an admin | Processed |
States none | Processed. A classifier reads the extracted text in short passages before sectioning. A clinical document is refused on its own with clinical_content_requires_baa, and the rest of the packet runs. A document with no text to read is refused with classification_unavailable. |
| Processing stopped by an incident | 403 incident_stop |
A refused request is not accepted, stored, or billed. POST /v1/scan and the AI, STEG, and EDITS checks are not affected by this gate.
Billing
Consistency costs 6 SCU per page (an image document counts as one page).
| Item | SCU |
|---|---|
| PDF page in a packet | 6 SCU per page |
| Image document (PNG, JPEG, TIFF) | 6 SCU, counted as one page |
| Text tokens, embedded images | Not billed on the packet path |
| Refused request, abandoned job | 0 SCU |
A 3-page PDF plus two photos is 5 pages: 5 pages x 6 SCU = 30 SCU. Each delivered packet records one usage entry. A retry under the same Idempotency-Key records nothing more.
Playground runs on a Pro plan use the same rate. On the free tier, each run counts against the daily Playground upload quota.
See Billing And SCU for the rates that apply to POST /v1/scan.
Check the error codes
The API reference lists every 403, 404, 413, and 429 code with what to do next.
