No online service is risk-free. DenialFight limits file types, access, processing permissions and retention, but cannot guarantee that transmission, hosting or third-party AI processing will never be compromised.
1. Security scope
This statement describes operational safeguards for the DenialFight website and document-review workflow. It is informational and does not create a warranty, service-level agreement, fiduciary duty or guarantee beyond rights that cannot lawfully be limited. The Service is directed only to the United States, although a U.S. user may submit a denial issued by a non-U.S. company.
2. Upload controls
- Up to 20 direct PDF, JPEG, PNG, DOCX, TXT or ZIP uploads per review.
- Maximum 20 MB per uploaded file and 50 MB total compressed/direct upload size.
- ZIP archives are expanded only inside the isolated worker, with limits of 60 supported extracted documents, 20 MB per extracted file and 100 MB total expanded content.
- Archive path traversal, symbolic links, encrypted ZIP files, nested archives and suspicious compression ratios are rejected.
- File-extension, declared type, binary-signature and extracted-content checks before AI processing.
- Random, non-guessable review identifiers and isolated per-review directories.
- No public directory listing or public file URL.
- Same-origin request checks and submission rate limits designed to reduce abuse.
3. Encryption and access
The public dev service uses HTTPS for transmission through the web proxy. Review files are stored outside the public website directory with restrictive filesystem permissions. Operational access is limited to personnel and services that need it for deployment, incident response, lawful requests or support. Encryption and access control reduce risk but do not eliminate it.
4. AI execution boundary
The document review runs through an OpenAI AI service non-interactively inside a shared, isolated worker authenticated through a server-managed authorization. The DenialFight container receives only a private worker URL and shared job directory; it does not receive credentials or mount the worker’s authorization home. Jobs use read-only sandbox settings, ignored user configuration, ignored repository rules and ephemeral session mode. The trusted worker builds the review instruction; the public client cannot supply commands, working directories, model flags or a system prompt.
The instruction forbids shell commands, arbitrary file access, contacting third parties, accessing other jobs or obeying instructions found inside an uploaded document. It permits controlled web search for generic public sources needed to identify procedures, regulators, licensing directories and resources, while prohibiting private document identifiers in search queries. Extracted content is marked as untrusted evidence. These controls reduce prompt-injection and persistence risk; they do not prove that every malicious document, inaccurate source, model error or software vulnerability will be detected.
5. Model-training and account controls
DenialFight does not intentionally opt in to sharing uploaded documents or generated answers for model training or evaluation and does not submit user content through feedback controls. Ephemeral AI processing prevents job session rollout files. OpenAI data use is governed by the authorized ChatGPT account’s plan, Data Controls and applicable terms; there is no separate documented application-level training switch that overrides account-level controls.
This configuration is not the same as contractual zero data retention. Processor safety, abuse-monitoring, security or legal-compliance retention may still apply. DenialFight will not describe the deployment as zero-data-retention unless the applicable provider has approved and enabled that control.
6. Ten-day deletion
Each review receives an expiration timestamp at upload. DenialFight automatically removes the entire review directory—original uploaded files, extracted ZIP contents, extracted text, rendered images, user description, job metadata, free preview, full report, appeal documents and complete ZIP package—from active servers within 10 days after upload. A user may invoke immediate deletion from the completed or failed review interface.
Deletion is irreversible. Users must keep their own originals and download any purchased package promptly after delivery is enabled. Small security, transaction, consent or access-log records may remain where needed and are designed not to include full document contents. Legal holds or incident investigations can require narrowly limited preservation.
7. Processor retention boundary
DenialFight’s 10-day promise applies to its active servers. OpenAI, hosting, payment and any future AI processor controls its own infrastructure and may keep limited records under its business terms. DenialFight selects business/API products with no-training defaults or commitments, uses paid or enterprise configurations for sensitive documents and requests downstream deletion where applicable, but cannot promise a shorter processor period than the provider contract allows.
8. Secrets and deployment
API credentials are supplied to the runtime through a server-side secret file and are not embedded in browser code, generated pages or API responses. Containers run as an unprivileged operating-system user. Uploaded review data is mounted separately from immutable application releases so normal releases do not copy claim files.
9. Payments
Development checkout may run as a local non-charging simulation or through Lemon Squeezy Test Mode. The local simulation confirms automatically, collects no card data and charges $0. Lemon Squeezy Test Mode uses provider-hosted checkout and test transaction data but transfers no real funds. In either environment, package access follows a server-confirmed event for that review. When live mode is activated, payment-card entry will occur on Lemon Squeezy-controlled checkout infrastructure and access will require a signature-verified paid-order webhook. DenialFight does not store full payment-card numbers. Users should verify the checkout domain, environment and merchant disclosures before proceeding.
10. Incident response
DenialFight investigates suspected unauthorized access, contains affected systems, preserves proportionate evidence, rotates credentials and notifies affected people, regulators, service providers or law enforcement when applicable law requires. For consumer health information, the FTC Health Breach Notification Rule and state health-privacy laws may impose additional notice duties.
11. User precautions
- Redact Social Security numbers, full bank details, passwords, unrelated medical records and information unnecessary to the denial.
- Upload only material you are authorized to disclose to DenialFight and the listed processors.
- Use a trusted device and network, close the review on shared devices and retain independent copies.
- Verify the original denial, all deadlines, citations, addresses and generated statements before acting.
- Report a suspected security issue to security@denialfight.com without attaching sensitive evidence to the first email.
12. Changes and contact
Controls, processors and threats change. We update this statement when the workflow materially changes and conduct release checks of API health, routes, links and the principal upload flow. Security reports: security@denialfight.com. Privacy requests: privacy@denialfight.com. Last updated July 31, 2026.
Questions or requests?
Use the dedicated address so your message reaches the correct review queue. Email is not an emergency service and does not extend an insurance or legal deadline.
privacy@denialfight.com