TRUST CENTER

Verify the badge. Forget the person.

Status Post needs to know you work in a hospital. It does not need to know your name, and it is being built so that it cannot find out. This section explains exactly how, in enough detail that someone outside the company can check it.

How verification works

The tier ladder — invite, registry, work email, badge photo — what each one covers, and the two things we will never do.

What we store

The entire record we keep about you, and the list of fields we deliberately do not have.

Transparency report and warrant canary

Legal demands received, what we were able to hand over, and the canary.

HIPAA, honestly

We are not a covered entity, and nobody should tell you otherwise. What that actually means for what you post.

The four principles under all of it

  • Verify the attribute, not the identity. The question is "does this person work in US healthcare," never "is this person Jane Smith."
  • Never run face matching. No face geometry is ever extracted from anything you send us. This is a permanent line, not a current setting.
  • Never persist the artifact. A badge photo is processed in memory and discarded — not to disk, object storage, logs, a queue, a backup or a training set.
  • Make it externally auditable. "Never stored" is worth nothing if we are the only ones saying it. The design is published here, and we intend to have the pipeline independently attested.

Design for the subpoena. The correct answer to "who wrote this?" is we do not know — and it should be literally true, not a policy we promise to keep. The key that names a member's stories is held on their device, so there is no table to disclose and no query to run. Every field we do not have is a field we cannot be compelled to produce.