Outcomer is deployed as a container inside your own cloud environment, under your existing security, identity and governance controls. It reads the files you point it at, prepares the Case Orientation Report, and writes it back — all within your perimeter.
No claim, evidence or customer data is ever sent to Outcomer.
Outcomer is installed the way any enterprise workload is: from your cloud provider’s marketplace, into your own subscription. It runs where your data already lives, under the controls you already operate. There is no Outcomer-hosted endpoint that your claim data is sent to.
The model runs in your estate too — against your own model deployment in your own subscription, called over a private endpoint inside your network. The software runs in your environment, the model runs in your environment, and nothing about the claim leaves your tenancy.
A versioned, signed feed of the requirements — the same corpus described on the governance page. Updated on a controlled schedule as requirements change. It contains no customer data: it is public regulatory material, prepared and versioned. You can inspect exactly what each version contains and when it applied.
The corpus is the only inbound dependency.
Claim, claimant, medical, policy and evidence data stays in your systems. The Case Orientation Report is written back into your estate, not sent anywhere. No claim data is transmitted to Outcomer for processing, training or support. Your examiners’ determinations never leave your perimeter.
Nothing claim-related crosses the boundary outbound.
Every Case Orientation Report is a complete, standalone document written into your estate. It does not depend on a live connection to Outcomer to be read, relied upon or produced to a regulator. If Outcomer disappeared tomorrow, every report you have already prepared remains intact and usable in your systems.
The container runs under your identity and access management. Who can invoke it, and who can read the reports, is governed by your existing roles — not by an Outcomer account system.
It sits inside your own network, subject to your egress rules, your segmentation and your monitoring. The corpus channel is the only external path, and it is one you can inspect and restrict.
Every run happens under your logging and observability stack. What was prepared, when, and against which corpus version is recorded in your systems alongside everything else you audit.
Your region, your residency. Because the workload runs in your subscription, data residency is whatever your environment already enforces. There is no second jurisdiction to reason about — the data never moves.
Policies, access control, change management and incident response are documented and operating, and independent attestation is in progress. Penetration testing, source-code escrow and technical documentation are available on request.
Because your data never reaches us, support works differently from a hosted service — and more safely. We cannot see into your instance, so diagnosis works from what you choose to share rather than from access we hold.
The deployment model, the boundary, the corpus channel and the escrow arrangement are open to your security and procurement review before anything is installed. We expect the questions, and the architecture is built to answer them.