Skip to content
FonteumPublic-records evidence

OPERATING STANCE

sources with data

Integrated, with-data, fresh, and complete are different grains.

As of August 18, 2026: 111 active source-registry rows were integrated, 90 snapshot source IDs had a positive record count, and 70 had a positive-data observation within 45 days. Sources complete: not aggregated; No platform-wide source-completeness count is published. Completeness is source-specific and must be evaluated against the named source's expected scope. The 13 represented state Medicaid jurisdictions are a separate coverage measure. Fonteum does not currently hold SOC 2.

Read the audit pack →

What Fonteum is · What Fonteum is not

Named public records, with transformations labeled.

Fonteum is
Fonteum is not
A public-records data platform. Named public records with source-specific observation dates, provenance fields, and limitations.
A data enrichment vendor.
Available provenance and limitations exposed with public fields.
A trust-score or rating provider.
A source-cited view of supported records from named public publishers.
An independent verifier of provider credentials.
A pipeline with published methodology versioning.
A claims processor or clearinghouse.
Honest about what we do and do not hold.
An aggregator of claims, EHR, or prescription-transaction data.

What Fonteum does not do

No enrichment. No scoring. No inference.

Present a proprietary provider quality or reliability score.
Infer demographics, market segments, or clinical outcomes.
Aggregate commercial claims data, EHR data, or Rx transactions.
Source from consumer demographics lists or marketing databases.
Republish data from restricted-distribution registries.
Assert credentials not traceable to a named public source.

Data not ingested

Explicit rejection list.

Commercial medical claims (clearinghouse or insurer-derived)
Electronic health record extracts of any kind
Prescription transaction data
Consumer demographic or behavioral datasets
Marketing list aggregators
Scraped third-party directory data
State medical board membership rosters
NMLS Consumer Access records
ABMS / CertiFacts certification records

Security posture

No certifications we don't hold.

Fonteum is not SOC 2 attested and does not currently hold a SOC 2 (Type 1 or Type 2), HIPAA, or ISO 27001 attestation, and displays no badge it does not hold. The hosting and data tiers run on SOC 2 Type 2 attested infrastructure (Vercel, Supabase). For procurement requiring a specific attestation, contact security@fonteum.com.

See pricing →

Infrastructure: Vercel (application hosting) + Supabase (managed Postgres, row-level security enforced). Encryption in transit (TLS 1.2+) and at rest. No service-role keys shipped to the browser.

HITRUST i1 evaluation planned for 2027 — i1 (Implemented, 1-year) is the appropriate scope for a no-PHI public-data platform. HIPAA covered-entity status is not applicable — Fonteum processes no PHI.

Vulnerability disclosure: security@fonteum.com · /.well-known/security.txt (RFC 9116).

BAA availability

BAA template on request.

Because Fonteum processes no PHI, BAA execution is typically not required under HIPAA for data ingestion. The template exists as a procurement formality for partners whose internal compliance review requires a signed BAA regardless of processing scope.

Download audit pack (includes BAA template) →

Customer evidence

Pilot intake open.

Fonteum does not currently hold SOC 2. Customer evidence published as pilots close. No fake logos, no anonymous testimonials.

Incident disclosure policy

72-hour incident disclosure. Public corrections log.

If a confirmed unauthorized access to user data is discovered, Fonteum notifies affected parties within 72 hours of confirmation and posts a public statement naming the scope of access, the affected data classes, the time window, and the remediation steps taken.

Data-quality incidents (a wrong figure on a live page) follow the same corrections workflow and are logged below alongside doctrinal corrections. Fonteum has not had a breach to date. The policy exists so the threshold is documented.

Selected dated audit note

Public-data corrections and audit notes.

Dated static correction log · 1 entry · not a live source-freshness feed

  1. 2026-07-12

    Accepted

    Public claims audit · Copy correction

    Public copy now distinguishes source-release, ingestion, and observation dates. The OIG LEIE production serving table held 68,055 rows from the May 8, 2026 source release when checked July 12; that observation is not a current-file claim.

Read the complete corrections and methodology log →

What’s on file, by the numbers

Platform snapshot · 2026-08-18

13.4Mproviders & companiesProviders, organizations, owners, and facilities on file
26.2Msource-linked factsSource-linked field facts in the dated platform snapshot
90sources with dataDistinct snapshot source IDs with at least one positive record count
70fresh sourcesDistinct source IDs whose latest positive-data snapshot falls within the preceding 45 days
111sources integratedActive registry rows; integration does not establish a load
13state Medicaid jurisdictionsDistinct states represented in the state-exclusions serving table

Integrated, with-data, and fresh-observation counts are separate. No platform-wide source-completeness count is published. Completeness is source-specific and must be evaluated against the named source's expected scope. State coverage is a separate jurisdiction measure.

Source authority is record-specific

Use the issuer named on the record.

Fonteum spans federal, state, and global public publishers. A source page or returned record identifies its issuer and dataset where that metadata is available. A platform registry count does not assign every page to one authority or establish loaded, fresh, or complete coverage.

Browse source records and their stated limitations →

Reproducible by design

Inspect the evidence each published figure actually supplies.

Source and date

Research pages expose the named public file and observation date where those fields are available. Source-file SHA-256 coverage is separate; facts do not currently link deterministically to signatures.

Available derivation

Studies with a retained release and committed derivation link the SQL or method used. Other studies state the evidence and reproduction limits they actually have.

Daily observations

Dated table row-count observations can detect local drift. They do not imply that an upstream publisher released or Fonteum ingested new data that day.

Named medical review

Reviewed by Jennifer Montecillo, MD, medical reviewer. Non-practicing medical reviewer.

Read the full provenance and attestation methodology →

Request access