Home / Security approach

LOCAL PROCESSING. DELIBERATE CONTROLS.

Trust is in
the details.

Local processing is only one part of a responsible engagement. Private intake, approved storage and backup protections, human accountability, and a written data-handling plan matter too.

SERVICE APPROACH · CONTROLS CONFIRMED PER ENGAGEMENT

Configured local workflow.

The configured workflow uses local OCR and deterministic checks on a Cauldron operator’s Windows workstation to help organize records and surface possible discrepancies. A reviewer checks source evidence and applicable terms. It is not a promise that processing takes place on your premises or that every part of the workflow is offline.

Client records begin in an audit-specific Dropbox file request after pre-intake checks. Uploads are not automatically synchronized; an operator deliberately imports selected files for each audit. Working copies, extracted text, findings, and reports are handled locally under the agreed engagement controls.

Local processing does not, by itself, establish encryption, isolation, compliance, or an independently verified level of security.

Agree the controls before the transfer.

These are engagement requirements to define and verify—not blanket claims that every control has already been deployed or independently audited.

01

Scope and data minimization

Identify the records needed, the completed-load review period, and information that can be omitted or redacted. Do not provide unrestricted system access when a limited export will do.

02

Private transfer and deliberate import

Use a separate private Dropbox file request per audit. Confirm the actual destination and permissions, then deliberately download or import only the selected files. A file request is not a synchronization connection.

03

Access and accountability

Agree who may access the records and who validates findings and authorizes follow-up. The current application has one trusted operator role; active trusted operators can access all client audits. Application MFA, SSO, and per-client operator permissions are not implemented.

04

Working storage and backups

Before confidential intake, verify and record the approved working-storage and backup protections. The application does not itself encrypt its database, original files, extracted text, reports, or backup bundles, and automatic encrypted offsite disaster recovery is not established.

05

Retention, incidents, and changes

Set retention and deletion responsibilities, backup treatment, incident contacts, notification terms, and approval for material changes before records are accepted.

Software assists. People authorize.

OCR and deterministic checks can be incomplete or wrong. Relevant amounts, rate terms, supporting documents, duplicates, credits, payment allocation, and exceptions need human source review. A flag is not evidence that a payer owes money.

The carrier controls which findings to pursue and payer communications. Cauldron does not automatically contact payers, submit collections, change accounting books, transfer funds, or debit a bank account. The public website does not connect to accounting systems or initiate payments.

The website is not the processing environment.

This is a marketing and inquiry site. It does not contain an invoice portal, an AI model, a financial-document upload endpoint, or a payment-processing service.

Contact inquiries are handled by the website’s configured form provider and are separate from client-record handling. Only submit business contact information and a high-level description of your needs. Do not submit invoices, bank information, tax IDs, passwords, driver records, or other confidential documents.

The site ships without advertising trackers, embedded third-party chat, or remotely loaded fonts. Cloudflare hosting and the form provider may still process technical information and logs. See the Privacy Notice.

Clear boundaries. No borrowed badges.

This website does not claim SOC 2 or ISO certification, a completed independent security audit or penetration-test attestation, end-to-end or zero-knowledge encryption, or compliance with a specific regulatory framework. Dropbox’s provider controls are separate from the workstation and do not certify Cauldron; see Dropbox’s security overview.

No particular accounting-software integration, recovery amount, recovery rate, payment timing, accuracy percentage, savings, or recovery is guaranteed. We proceed only within the written scope and after the required pre-intake checks are complete.

Start with your requirements.

Tell us about your workflow and security expectations—without sending financial documents.

Talk with the founder