Scope and data minimization
Identify the records needed, the completed-load review period, and information that can be omitted or redacted. Do not provide unrestricted system access when a limited export will do.
LOCAL PROCESSING. DELIBERATE CONTROLS.
Local processing is only one part of a responsible engagement. Private intake, approved storage and backup protections, human accountability, and a written data-handling plan matter too.
SERVICE APPROACH · CONTROLS CONFIRMED PER ENGAGEMENTThe configured workflow uses local OCR and deterministic checks on a Cauldron operator’s Windows workstation to help organize records and surface possible discrepancies. A reviewer checks source evidence and applicable terms. It is not a promise that processing takes place on your premises or that every part of the workflow is offline.
Client records begin in an audit-specific Dropbox file request after pre-intake checks. Uploads are not automatically synchronized; an operator deliberately imports selected files for each audit. Working copies, extracted text, findings, and reports are handled locally under the agreed engagement controls.
These are engagement requirements to define and verify—not blanket claims that every control has already been deployed or independently audited.
Identify the records needed, the completed-load review period, and information that can be omitted or redacted. Do not provide unrestricted system access when a limited export will do.
Use a separate private Dropbox file request per audit. Confirm the actual destination and permissions, then deliberately download or import only the selected files. A file request is not a synchronization connection.
Agree who may access the records and who validates findings and authorizes follow-up. The current application has one trusted operator role; active trusted operators can access all client audits. Application MFA, SSO, and per-client operator permissions are not implemented.
Before confidential intake, verify and record the approved working-storage and backup protections. The application does not itself encrypt its database, original files, extracted text, reports, or backup bundles, and automatic encrypted offsite disaster recovery is not established.
Set retention and deletion responsibilities, backup treatment, incident contacts, notification terms, and approval for material changes before records are accepted.
OCR and deterministic checks can be incomplete or wrong. Relevant amounts, rate terms, supporting documents, duplicates, credits, payment allocation, and exceptions need human source review. A flag is not evidence that a payer owes money.
The carrier controls which findings to pursue and payer communications. Cauldron does not automatically contact payers, submit collections, change accounting books, transfer funds, or debit a bank account. The public website does not connect to accounting systems or initiate payments.
This is a marketing and inquiry site. It does not contain an invoice portal, an AI model, a financial-document upload endpoint, or a payment-processing service.
Contact inquiries are handled by the website’s configured form provider and are separate from client-record handling. Only submit business contact information and a high-level description of your needs. Do not submit invoices, bank information, tax IDs, passwords, driver records, or other confidential documents.
The site ships without advertising trackers, embedded third-party chat, or remotely loaded fonts. Cloudflare hosting and the form provider may still process technical information and logs. See the Privacy Notice.
This website does not claim SOC 2 or ISO certification, a completed independent security audit or penetration-test attestation, end-to-end or zero-knowledge encryption, or compliance with a specific regulatory framework. Dropbox’s provider controls are separate from the workstation and do not certify Cauldron; see Dropbox’s security overview.
No particular accounting-software integration, recovery amount, recovery rate, payment timing, accuracy percentage, savings, or recovery is guaranteed. We proceed only within the written scope and after the required pre-intake checks are complete.
Tell us about your workflow and security expectations—without sending financial documents.
Talk with the founder