Metadata-Version: 2.4
Name: upstream-data
Version: 3.40.0
Summary: Generate realistic synthetic healthcare claims for testing your revenue cycle pipeline. Zero PHI. Known denial patterns. API-first.
Project-URL: Homepage, https://data.upstream.cx
Project-URL: Documentation, https://data.upstream.cx/docs
Project-URL: Repository, https://github.com/Upstream-Intelligence/upstream-data
Project-URL: Trust Center, https://data.upstream.cx/trust
License: Commercial
Keywords: ai-evaluation,claims,healthcare,hipaa,revenue-cycle,synthetic-data
Classifier: Development Status :: 4 - Beta
Classifier: Intended Audience :: Developers
Classifier: Intended Audience :: Healthcare Industry
Classifier: Programming Language :: Python :: 3.12
Classifier: Topic :: Scientific/Engineering :: Artificial Intelligence
Requires-Python: >=3.12
Requires-Dist: defusedxml>=0.7.1
Requires-Dist: faker>=37.0.0
Requires-Dist: fastapi>=0.115.0
Requires-Dist: google-cloud-storage>=2.18.0
Requires-Dist: huggingface-hub>=1.17.0
Requires-Dist: mcp>=1.27.2
Requires-Dist: numpy>=2.3.0
Requires-Dist: orjson>=3.10.0
Requires-Dist: polars>=1.30.0
Requires-Dist: pyarrow>=20.0.0
Requires-Dist: pydantic-settings>=2.10.0
Requires-Dist: pydantic>=2.11.0
Requires-Dist: pyyaml>=6.0.2
Requires-Dist: requests>=2.32.0
Requires-Dist: rich>=14.0.0
Requires-Dist: scipy>=1.16.0
Requires-Dist: stripe>=12.0.0
Requires-Dist: structlog>=25.4.0
Requires-Dist: tenacity>=9.1.0
Requires-Dist: typer>=0.16.0
Requires-Dist: uvicorn[standard]>=0.34.0
Description-Content-Type: text/markdown

# Upstream Data

Synthetic healthcare operating-environment infrastructure for the Upstream ecosystem.

This repo is the source-of-truth backend/data substrate plus a standalone
`marketing/` self-serve marketplace site for `data.upstream.cx`. The Python package
generates synthetic claims, commercial pack metadata, provenance artifacts,
quality gates, delivery contracts, bridge payloads, and paid-depth simulation
artifacts. The public surface must not expose paid-depth artifacts, bulk
generated data, real-payer-truth claims, or enterprise/SLA promises without an
approved agreement.

## Product Canon

Upstream Data is a synthetic healthcare operating environment for revenue cycle,
payer behavior, and healthcare AI evaluation. It is not just datasets and not a
data repo.

It sells:

- specialty-specific synthetic data packs for claims, denials, remittances,
  auths, documents, events, and workqueues
- scenario-lab simulations for auth tightening, denial spikes, payment
  slowdown, underpayment drift, documentation crackdowns, and regional friction
- agent evaluation environments for claim scanning, denial routing, appeal
  drafting, prior-auth readiness, underpayment detection, payment posting, and
  workqueue prioritization
- synthetic regression testing fixtures for healthcare SaaS release gates
- private synthetic twins from aggregate stats only, never PHI or raw claims
- public-safe benchmark standards: ClaimEval, DenialBench, PayerSim,
  RCM Arena, and PaymentPostBench
- governed distribution with release locks, source manifests, synthetic-only
  attestations, validation scorecards, checksums, tiers, and public/private
  boundaries

Current commercial posture: **Upstream Data — self-serve marketplace**. Buy
synthetic-only packs at data.upstream.cx (Starter $299 / Professional $799 /
sample free). Delivered by signed link with a synthetic-only attestation, source
manifest, and provenance artifacts. Not enterprise-certified, not SLA-backed,
not legal/billing advice, not real payer truth. Free samples use the access
request flow.

Core promise: build, test, demo, benchmark, and stress-test healthcare
revenue-cycle software safely using realistic synthetic healthcare worlds.

Buyers are healthcare AI startups, RCM software vendors, clearinghouses, EHR/PM
vendors, PE-backed operators, MSOs/DSOs, specialty groups, consultants, and
revenue intelligence vendors. They buy because they need realistic healthcare
workflows without touching PHI or customer claims.

The moat is specialty-specific rules, payer archetypes, scenario DSL,
transaction lifecycle simulation, synthetic document graphs, agent eval corpora,
governance/paywall compilation, release ledgers, public methodology standards,
and deep integration with Upstream's care-intelligence platform.

## Current State

- v3.39 preview depth gates now require timeline-first economy intent linkage,
  explicit specialty pathways, service-code coverage, replay scorecards,
  public redaction, and paid evidence bundles before a pack can be
  preview-ready.
- The Python package version is `3.39.0`; generated bridge, product-canon,
  and release-artifact versions remain separate contract versions and are
  documented in `docs/product/v3.28-launch-surface-version-hygiene.md`.
- 37 commercial packs synthesize through one shared engine: the 20-pack
  Upstream-aligned core plus 17 new vertical-moat packs.
- Every synthesis run emits one dataset artifact plus 65 required release artifacts.
- Public samples expose only the dataset, public sample manifest, source manifest,
  and synthetic-only attestation.
- Claim-realism, claim-edit, adjudication-trace, transaction, world-model,
  event, episode, operating timeline, synthetic document, trace graph,
  agent-evaluation, evaluation harness, benchmark-suite, and payer/contract
  simulator artifacts are paid-depth by default.
- The v3.29 workflow replay engine emits paid-depth replay instances,
  public-safe replay indexes, replay manifests, and validation reports so the
  portable unit of value is a complete synthetic RCM episode with evidence,
  documents, remits, workqueue items, agent tasks, expected outcomes, and
  reproducible trace context.
- The v3.30 category flywheel engine reads generated workflow replays and emits
  aggregate-signal intake reports, public-safe payer behavior indexes, RCM
  knowledge graph summaries, synthetic-to-real aggregate transfer deltas, vendor
  certification scorecards, RCM chaos scenarios, enterprise audit replay
  checksum manifests, scenario provenance, and validation reports.
- The v3.31 replay runner loads generated workflow replays, steps timelines,
  emits runtime events, scores agent/product decisions, exports audit traces,
  and produces validation reports for CI regression, vendor certification, and
  buyer-specific baseline testing.
- The v3.32 CI regression runner turns replay runtime output into release gates
  with weighted benchmark suites, JSON scorecards, Markdown reports, JUnit
  output, PHI-boundary checks, failure reports, and optional baseline drift
  comparison.
- The v3.33 timeline-first economy kernel emits world-derived operating events,
  claim intents, impact reports, manifests, and validation gates before
  downstream claim/replay artifacts are interpreted.
- The v3.34 replay OS command surface productizes the core primitive:
  Synthetic RCM World -> Replay -> Scorecard -> Certification. It adds
  `upstream-data replay validate`, `replay run`, `replay score`,
  `replay compare`, diagnostic scorecard dimensions, flagship suite alignment,
  and a buyer-facing Synthetic RCM OS bundle layout.
- The v3.35 enterprise launch compiler produces a single auditable launch gate:
  version matrix, public-surface governance report, adjacent-repo audit,
  provider live-readiness, provider runtime report, hosted control-plane
  readiness, definition-of-done checklist, production-readiness gate, and
  optional local operator launch proof.
- The v3.36 hosted fulfillment proof runtime connects entitlement grant,
  idempotent queue enqueue, stale-worker reconciliation, generation worker
  execution, control-plane indexing, signed URL access checks, expiry blocking,
  revocation blocking, provider-runtime gating, and audit evidence behind
  `upstream-data hosted-fulfillment-proof`.
- The v3.37 provider hardening replaces the single generic live-provider
  endpoint with provider-specific live adapter endpoints, tightens live
  readiness requirements, makes commercial claim generation fail closed when a
  procedure family lacks a service-code mapping, and removes scanner-risky
  public data-site wording around de-identification and real payer behavior.
- The v3.38 flagship world command (`upstream-data flagship-world`) builds the
  ABA reference path from 12-month economy timeline through workflow replays,
  scorecard JSON/Markdown/JUnit, certification packet, public redacted export,
  paid evidence bundle, trust view, knowledge graph, policy feed, and outcome
  impact artifact.
- The v3.39 pack maturity gate marks ABA, dental, SNF-MA, imaging, and DME as
  `flagship-deep`; home-health, PT/OT, and oncology as `trace-complete`; and
  keeps the remaining commercial packs at `synthetic-calibrated` until they
  earn deeper preview evidence.
- Longitudinal episode journeys, typed scenario DSL outputs, dataset locks,
  release ledgers, and buyer package manifests are implemented as v1.8
  infrastructure.
- Buyer bundles are typed SKU contracts with access tiers, row/artifact limits,
  validation gates, package manifests, and validation reports.
- Real transaction surface exports are implemented as non-certified synthetic
  dialects for 837-family claims, 835 remittance, 276/277 status, 275
  attachments, and FHIR-like Claim/EOB workflows.
- The v2.1 synthetic healthcare world model creates persistent synthetic
  members, provider panels, payer profiles, employer plans, benefit designs,
  payer policy rules, contract terms, and operations states so claims fall out
  of a simulated healthcare economy instead of independent row generation.
- The v2.2 evaluation harness emits paid-depth benchmark-suite manifests and
  release-grade harness reports for row plausibility, longitudinal plausibility,
  denial mix, remittance balance, specialty pathway, artifact completeness,
  synthetic boundary, buyer bundle completeness, and hard-negative mutation
  detection.
- The v2.3 configurable payer/contract simulator emits aggregate-only synthetic
  payer archetype, fee schedule behavior, auth strictness, appeal behavior,
  payment velocity, denial-family weight, underpayment, regional-friction, and
  contract/carve-out outputs for enterprise scenario labs.
- The v2.4 production API/job system runs local service-token generation jobs,
  materializes buyer packages, writes usage metering and audit logs, emits
  signed URL descriptors, and exports backend bridge contracts for async job
  execution.
- The v2.5 governance layer gates public, Hugging Face, bridge, MCP, skills,
  and community publication candidates with allowlists, paid/internal denylists,
  row limits, and leakage checks.
- The v2.6 customer QA package builds buyer-facing methodology, source,
  attestation, checksum, reproducibility, limitations, and validation scorecard
  artifacts from a real generated release.
- The v2.7 adjacent repo audit validates backend-only `upstream` routes,
  `upstream-mcp` synthetic-data tools, `upstream-skills` examples, and
  `upstream-community` methodology fixtures without frontend or website edits.
- The v3.0 vertical expansion adds executable ASC, urgent care, dermatology,
  gastroenterology, urology, OBGYN, endocrinology, nephrology, speech therapy,
  chiropractic, wound care, infusion centers, rural hospital, FQHC/RHC,
  emergency medicine, anesthesia, and specialty pharmacy packs.
- The v3.1 data-science controls layer emits paid-depth population, correlation,
  seasonality, outlier, and scenario-effect evidence for every synthesis run.
- The v3.2 synthetic twin layer emits aggregate-only calibration configs,
  calibration reports, and reproducibility packets for enterprise scenario labs
  without accepting raw claims, PHI, or customer row-level records.
- The v3.3 policy-as-code payer engine emits deterministic paid-depth decisions
  for authorization, documentation, modifiers, frequency limits, bundling,
  downcoding, appeal routing, payment delay, underpayment, and recoupment while
  explicitly disclaiming real payer policy, coding advice, and payment advice.
- The v3.4 contract/fee-schedule engine emits paid-depth line-level synthetic
  contract economics for Medicare-indexed logic, commercial multipliers, case
  rates, per diems, dental PPO leasing pressure, COB, stop loss, carve-outs,
  recoupment risk, and underpayment variance without reproducing official fee
  schedules.
- The v3.5 ecosystem contract sync gate makes adjacent-repo drift fail closed:
  `upstream` backend payload versions, pack ids, route markers, marketing data
  catalog ids, MCP tools, skill examples, and community fixture markers must
  match generated bridge contracts before launch.
- The v3.6 synthetic healthcare operating contract emits one canonical contract
  tying `upstream-data`, `upstream` backend, MCP tools, skills, community
  fixtures, marketing catalog sync, parity workflows, agent evals, document
  graph, vertical readiness, entitlements, private synthetic twin rules,
  governed marketplace gates, benchmark standards, release certification, and
  aggregate-only feedback loops together.
- The v3.7 company operating-system contract adds the canonical RCM ontology,
  trace engine, day-by-day operating timeline, enterprise control plane,
  code-gated pack certification, scenario marketplace, SDK/CI distribution
  surfaces, benchmark canon, sales proof package, governance-safe feedback loop,
  and category narrative.
- The v3.8 product-canon export writes public-safe and adjacent-repo-safe
  product definition payloads for backend, MCP, skills, community, and
  data-buyer marketing surfaces without exposing paid-depth artifacts.
- The v3.9 canonical ecosystem sync wires those generated contracts into
  `upstream`, `upstream-mcp`, `upstream-skills`, `upstream-community`, and the
  data-buyer marketing catalog, with cross-repo audit proof that bridge version
  `2026-05-27.v3.4` is coherent across 4 of 4 adjacent repos.
- The v3.10 semantic endpoint contract pass adds distinct backend/MCP metadata
  surfaces for episode manifests, adjudication trace summaries, transaction
  surface manifests, and payer-contract simulator manifests/reports so tools no
  longer alias to broader generic endpoints.
- The v3.11 durable control-plane ledger adds a local SQLite state layer for
  entitlements, generation jobs, signed URL lifecycle, usage metering, audit
  persistence, and revocation without storing generated rows, PHI, customer
  data, or real-payer-truth claims.
- The v3.12 provider live-readiness preflight fails closed unless live storage,
  signed URL, Stripe, webhook, email, analytics, Hugging Face, entitlement, and
  revocation configuration is present.
- The v3.13 durable queue/worker runtime persists generation-job queue state,
  idempotent enqueue decisions, worker claims, succeeded/failed outcomes, and
  optional control-plane indexing for local production-shaped execution.
- The v3.14 MCP semantic route gate makes adjacent-repo audits fail closed when
  expanded synthetic-data MCP tools call the wrong backend endpoint.
- The v3.15 live Stripe provider bridge makes adjacent-repo audits fail closed
  when `upstream` loses data-product checkout price settings, Stripe Checkout
  Session creation, webhook signature verification, or live-provider tests.
- The v3.16 category ownership packet emits and validates enterprise trust,
  scientific defensibility, benchmark standards, regression testing, developer
  distribution, marketplace contribution, and commercial operating-system
  artifacts so category ownership is executable instead of planning copy.
- The v3.17 category standard kit emits public-safe RCM ontology, benchmark
  specs, reviewer attestation, partnership, policy-intelligence, leaderboard,
  enterprise sales, developer ecosystem, and feedback-flywheel artifacts so
  category ownership can become an external standard without leaking paid depth.
- The v3.18 developer distribution kit emits public-safe Python SDK helpers,
  pytest fixtures, GitHub Action templates, Docker runtime contracts, dbt seeds,
  and DuckDB/SQLite/Snowflake/BigQuery loader templates with fail-closed leakage
  checks so buyers can embed the standard in CI and warehouse smoke tests without
  receiving paid corpora or commercial-depth internals.
- The v3.19 commercial launch packet emits EULA, data-use, support, refund,
  operator approval, publishing policy, entitlement, revocation, procurement,
  and launch-checklist artifacts with fail-closed guardrail and entitlement
  validation so paid fulfillment has a coherent launch packet before provider
  credentials go live.
- The v3.20 operator launch proof packet executes the local fulfillment chain:
  provider readiness, commercial launch packet, generation job, release gate,
  publication gate, entitlement grant/check, control-plane indexing, revocation
  drill, signed terms proof, usage metering, and audit proof. It reports local
  proof separately from production launch readiness so missing live credentials
  block launch without invalidating local evidence.
- The v3.21 provider adapter runtime executes every provider operation contract
  in local mode and fails closed in live HTTP adapter mode unless provider-
  specific live adapter env is configured for storage, signed URLs, email,
  analytics, entitlement, revocation, Stripe, and Hugging Face publication.
- The v3.22 operating artifact graph emits 12-month member timelines,
  synthetic document corpora, trace graph nodes, manifests, and validation
  reports so generated claims link back to benefits, authorization, policy,
  contract, remittance, payment posting, workqueue, appeal, and cash-impact
  context.
- The v3.23 embedded platform moat packet emits private synthetic twin, policy
  intelligence, benchmark standard, regression CI, external reviewer,
  marketplace contribution, enterprise trust, live control-plane, developer
  ecosystem, and category canon contracts with fail-closed validation.
- The v3.24 ecosystem standard packet emits reviewer network, pack
  certification, scenario marketplace, aggregate calibration, RCM digital twin
  studio, Agent Arena, trace-first explainability, policy-change intelligence,
  procurement, integration, feedback, partner, and public standard artifacts
  with fail-closed validation.
- The v3.25 network effects moat packet emits aggregate-signal consortium,
  payer behavior index, specialty council, synthetic policy backtesting, RCM
  chaos engineering, enterprise audit replay, customer baseline, workflow
  scoring, evidence graph, revenue impact, vendor certification, regulatory
  radar, and product-ladder artifacts with fail-closed validation.
- The v3.26 platform product canon emits the end-product contract for the
  synthetic healthcare world engine, scenario lab, private synthetic twin,
  healthcare AI evaluation platform, regression testing infrastructure,
  benchmark standard, governed marketplace, buyer segments, product promise,
  and moat components with fail-closed validation.
- The v3.27 workflow replay format emits a portable RCM episode replay schema,
  sample replay fixture, RCM knowledge graph contract, synthetic-to-real
  aggregate transfer tests, reviewer attestations, scenario provenance, buyer
  calibration report contract, Synthetic Claims OS SDK contract, agent rubric
  library, edge-case library, trust portal contract, refresh cadence, and
  integration badge artifacts with fail-closed validation.
- The v3.29 workflow replay engine makes that format executable inside
  synthesis output: full replay JSONL is paid-depth, while the public index is
  redacted and safe for methodology/catalog surfaces.
- The v3.30 category flywheel engine makes category ownership operational:
  workflow replays become indexes, transfer reports, certification evidence,
  chaos suites, provenance, and audit replay proof while rejecting PHI-like,
  raw-claim, customer-row, de-identification, and real-payer-truth inputs.
- The v3.31 replay runner makes workflow replay an executable test runtime:
  agents and products can be scored against expected actions, evidence refs,
  forbidden actions, timeline events, and audit traces.
- The v3.32 CI regression runner makes replay scoring embeddable in software
  delivery pipelines: `denialbench`, `paymentpostbench`, `authbench`, and
  `rcm-arena` suites emit pass/fail artifacts for release gates and vendor
  certification preflight.
- The v3.33 economy kernel makes the direction of realism explicit: persistent
  world state produces eligibility/auth/service/documentation events, claim
  intents, cash pressure, and workqueue burden before rows and replays.

## Core Commands

```bash
uv sync
uv run upstream-data synthesize --pack aba --rows 35 --seed 20260526 --format csv --scenario authorization-surge --output-dir tmp/aba
uv run upstream-data release-gate --output-dir tmp/aba
uv run upstream-data evaluation-report --output-dir tmp/aba
uv run upstream-data workflow-replay-report --output-dir tmp/aba
uv run upstream-data category-flywheel-report --dataset-dir tmp/aba --output-dir tmp/category-flywheel
uv run upstream-data replay-runner-report --dataset-dir tmp/aba --output-dir tmp/replay-runtime
uv run upstream-data ci-run --dataset-dir tmp/aba --output-dir tmp/ci-regression --suite denialbench --threshold 0.92
uv run upstream-data replay validate tmp/aba
uv run upstream-data replay run tmp/aba --mode local --output-dir tmp/replay-os-run --suite denialbench
uv run upstream-data replay score tmp/replay-os-run --output-dir tmp/replay-scorecard --rubric denialbench
uv run upstream-data replay compare tmp/replay-os-run/scorecard.json tmp/replay-os-run/scorecard.json --output-dir tmp/replay-compare
uv run upstream-data rcm-os-bundle --dataset-dir tmp/aba --output-dir tmp/rcm-os-bundle
uv run upstream-data population-control-report --output-dir tmp/aba
uv run upstream-data synthetic-twin-report --output-dir tmp/aba
uv run upstream-data category-ownership-packet --output-dir tmp/category-ownership
uv run upstream-data category-standard-kit --output-dir tmp/category-standard-kit
uv run upstream-data developer-distribution-kit --output-dir tmp/developer-distribution-kit
uv run upstream-data embedded-platform-moat --output-dir tmp/embedded-platform-moat
uv run upstream-data ecosystem-standard --output-dir tmp/ecosystem-standard
uv run upstream-data network-effects-moat --output-dir tmp/network-effects-moat
uv run upstream-data platform-product-canon --output-dir tmp/platform-product-canon
uv run upstream-data workflow-replay-format --output-dir tmp/workflow-replay-format
uv run upstream-data commercial-launch-packet --output-dir tmp/commercial-launch-packet
uv run upstream-data operator-launch-proof --output-dir tmp/operator-launch-proof
uv run upstream-data enterprise-launch-compiler --root-dir /Users/kevinrichards/Projects/upstream --output-dir tmp/enterprise-launch-compiler --include-operator-proof
uv run upstream-data hosted-fulfillment-proof --output-dir tmp/hosted-fulfillment-proof --pack aba --bundle sample --rows 5 --seed 20260528
uv run upstream-data payer-policy-report --output-dir tmp/aba
uv run upstream-data contract-fee-report --output-dir tmp/aba
uv run upstream-data payer-simulator-report --output-dir tmp/aba
uv run upstream-data generation-job-run --pack aba --rows 35 --seed 20260527 --format csv --scenario authorization-surge --bundle sample --output-dir tmp/job --idempotency-key local-proof --service-token local-service-token
uv run upstream-data generation-job-status --job-dir tmp/job
uv run upstream-data job-queue-init --db tmp/job-queue.sqlite
uv run upstream-data job-queue-enqueue --db tmp/job-queue.sqlite --pack aba --rows 10 --seed 20260527 --format csv --scenario authorization-surge --bundle sample --output-dir tmp/queued-job --idempotency-key queued-proof --service-token local-service-token
uv run upstream-data job-queue-run-next --db tmp/job-queue.sqlite --worker-id local-worker --control-plane-db tmp/control-plane.sqlite
uv run upstream-data job-queue-reconcile-stale --db tmp/job-queue.sqlite --worker-id operator-worker --older-than-seconds 300
uv run upstream-data job-queue-report --db tmp/job-queue.sqlite
uv run upstream-data control-plane-init --db tmp/control-plane.sqlite
uv run upstream-data control-plane-grant-entitlement --db tmp/control-plane.sqlite --buyer-id buyer-demo --pack aba --bundle sample --tier starter
uv run upstream-data control-plane-index-job --db tmp/control-plane.sqlite --job-dir tmp/job
uv run upstream-data control-plane-report --db tmp/control-plane.sqlite
uv run upstream-data provider-live-readiness --environment-name production --output tmp/provider-readiness.json
uv run upstream-data provider-adapter-runtime --pack aba --tier starter --mode local --output tmp/provider-runtime.json
uv run upstream-data huggingface-export-gate --source-dir tmp/distribution/samples/aba
uv run upstream-data bridge-governance --bridge-dir tmp/upstream-bridge
uv run upstream-data qa-package --source-dir tmp/aba --output-dir tmp/aba-qa
uv run upstream-data package-catalog
uv run upstream-data package-bundle --source-dir tmp/aba --package-dir tmp/aba-rcm --bundle rcm-simulation
uv run upstream-data validate-package --package-dir tmp/aba-rcm
uv run upstream-data scenario-dsl --input tmp/scenario.json --output tmp/scenario.compiled.json
uv run upstream-data distribution-bundle --rows 5 --seed 20260526 --format csv --phase phase-2 --output-dir tmp/distribution
uv run upstream-data upstream-bridge-bundle --output-dir tmp/upstream-bridge
uv run upstream-data ecosystem-contract-audit --root-dir /Users/kevinrichards/Projects/upstream --output tmp/v35-adjacent-contract-sync-audit.json
uv run upstream-data synthetic-healthcare-contract --output-dir tmp/v36-contract
uv run upstream-data company-operating-system --output-dir tmp/v37-company-os
uv run upstream-data company-product-canon-export --output-dir tmp/v38-product-canon
uv run upstream-data ecosystem-contract-audit --root-dir /Users/kevinrichards/Projects/upstream --output tmp/v39-adjacent-final.json
uv run upstream-data distribution-bundle --rows 2 --seed 20260527 --format csv --phase phase-v3 --output-dir tmp/v30-distribution
uv run upstream-data upstream-bridge-bundle --phase phase-v3 --output-dir tmp/v30-bridge
```

## Marketing Surface

```bash
cd marketing
npm install
npm run type-check
npm run build
```

The sample/enterprise access request route sends notifications through `RESEND_API_KEY`. Backend
persistence is opt-in and requires both `BACKEND_URL` or `NEXT_PUBLIC_API_URL`
and `DATA_WAITLIST_BACKEND_PATH`; this avoids hardcoding dead backend endpoints.

## Verification

```bash
uv run pytest -q -p no:cacheprovider
uv run ruff check .
uv run mypy src/upstream_data
uv run python -m compileall -q src tests
git diff --check
```

The same verification stack runs in GitHub Actions on pull requests, pushes to
`main`, and manual workflow dispatches through `.github/workflows/ci.yml`.

## Safety Boundary

Upstream Data is generated-from-scratch synthetic data only:

- no PHI;
- no customer data;
- no real patient records;
- no de-identification claims;
- no differential-privacy claims;
- no real-payer-truth claims;
- no clinical coding, payment, or legal advice.

See `docs/INDEX.md`, `.planning/CURRENT_STATUS.md`,
`.planning/REQUIREMENTS.md`, and
`docs/product/v3.36-hosted-fulfillment-runtime.md` for the current hosted
fulfillment runtime handoff.
