The questions a lab director or IT reviewer asks on a first call, answered plainly. IT-depth questions live in the IT & Security Review Packet's CAIQ table (customer documentation — sign in to read it); legal terms live in the Terms of Use — this page doesn't paraphrase either.
No, by design. BenchForge models economics and operations — workflow structure, costs, volumes, reimbursement assumptions. No patient identifiers, no specimen-level data, no results. Keeping PHI out of free-text fields is your responsibility under the Terms, and the product helps enforce it: support messages are screened server-side and rejected if they contain identifier-shaped text, and 835 remittance files are parsed entirely in your browser — the raw file never leaves your device. Because no PHI is processed, no BAA is required or offered.
Every figure is computed deterministically from inputs you can see and review — no black box. Cost per reportable, margins, capacity, turnaround, and the revenue cycle are solved from your workflow structure, staffing, schedule, and payer assumptions, and every headline stays marked provisional until you've reviewed the inputs it leans on. The full calculation set is documented in How every number is computed (sign in). To see how well the model tracks reality, reconcile against your actuals — the Leadership Summary then states model confidence as "within X% of actuals."
As accurate as its inputs — which is why the product is built around reviewing them. Figures stay marked provisional until you've confirmed the inputs they lean on, benchmarks are labeled illustrative until you swap in your own, and the reconcile loop measures the model against your actuals and states the result plainly. The known modeling gaps are listed openly on Deployment, security & what we model — if one of them matters to your lab, telling us is exactly the feedback early access is for.
Every tenant table is protected by Postgres Row-Level Security keyed to your workspace membership — a user can only ever read or write their own lab's rows, and every workspace write passes through one hardened, audited chokepoint that re-checks role and scope. An automated test asserts one tenant cannot read another's data. Data model & tenancy documents the data model itself, and the IT & Security Review Packet is the printable version for your IT team (both are customer documentation — sign in to read them).
Early access is concierge-onboarded: we turn your existing documents — SOPs, test menu, a P&L or LIMS/billing export — into a working model of your lab, with you reviewing every input. You get the full product: modeling, economics, the decisions register, imports, the 835 loop, and the exportable Leadership Summary. Two things to know going in: pricing is shared before GA, and during Early Access we may need to reset or migrate workspace data as the product evolves — we give advance notice, and you should retain your own exported copies (the Terms say the same).
The file never leaves your computer. An 835 is parsed entirely in your browser — it is never uploaded, never transmitted to us, and never written to our database in any form. Only the derived aggregate is saved: money by billing code, mapped to your assays.
That isn't a handling policy we promise to follow, it's a property of how the parser is built. It never reads the segments that carry names, member IDs or claim control numbers, and a test asserts that no identifier survives serialization — so the build fails if anyone changes that, including us. The 835 is the most identifier-dense file a lab touches, which is exactly why it is the one we made impossible to send.
A month's revenue is the sum across all your payers' files; each file adds, and re-importing the same file replaces its own entry. Drop each closed month's files and the "This month vs model" digest shows measured collections against the model, per assay.
It can, read-only and opt-in — or you can keep importing files, which many labs prefer.
File import is always available and needs nothing from your IT team: drop a CSV export, confirm the column mapping once, then each month's file is one click on the saved shape.
A read-only LIMS connection reads the same facts on a schedule, so nobody has to remember to export anything. Four limits are worth stating plainly, because they are why this isn't the liability it sounds like:
- It only ever reads. BenchForge issues read requests and nothing else — it cannot create, change or delete
anything in your LIMS, so it cannot disturb a validated system or become the reason an upgrade slips. Use a read-only account; a write-capable one grants risk you get nothing back for.
- It never takes patient data. Fields that look like identifiers, specimen IDs or result content are
excluded before anything is mapped, and we keep no sample of their contents. Volumes are counted in memory and the underlying records discarded — we can tell you how many samples ran without ever holding one.
- It doesn't know what anything costs. A LIMS holds structure, volumes and turnaround. Reagents, labour
rates, service contracts and amortisation are not in there, so your cost layer stays yours to enter. Anyone who tells you their tool reads your economics out of your LIMS is describing something a LIMS does not contain.
- You confirm before anything is imported. We show what the connection reads as real figures from your own
last three months — not as field names — and nothing flows until you have checked it. If a field later disappears or goes empty, we stop and say so rather than quietly importing a zero.
With the economics of that decision, yes: model the deployment scenarios, see what each does to cost, capacity and margin, and commit the decision so the forecast gets graded against what actually happens. BenchForge is not a LIMS and doesn't rate them.
Whether your lab is ready to run the selection at all — requirements, stakeholders, evidence, deployment fit — is a different question, and it has its own product: the LIMS Readiness Assessment — a one-time purchase from the same company under a deliberately different design: it runs zero-knowledge in your browser, so unlike BenchForge it cannot read your answers. The two share no data and no accounts; they meet only in your decision.
Many clinical LIMS run on-premise with no public address. A cloud connector genuinely cannot reach those, and we will tell you that rather than leave you retrying; file import covers that case fully.
Yes, with two limits worth knowing before you start rather than after.
What works anywhere. The two things BenchForge is actually for — a fully-loaded cost per test built from your workflow steps, and the binding constraint that gates your throughput, costed — are arithmetic about your bench. They do not care which country you are in. Set your display currency and your country of operation in Configure Lab → Financial Assumptions; every figure then reads in your currency, and the fee-schedule tools name your schedule (the EBM, the NABM, the MBS) rather than assuming ours.
Limit 1 — how you are funded. If your lab is paid a fixed budget rather than per test, choose Block budget as your funding model. The P&L then reports budget, operating cost, and surplus/(deficit) against it, instead of a revenue and margin you never see. Cost is modeled identically either way.
Limit 2 — one setting before fee-schedule repricing works. Loading a published schedule works out of the box: the importer reads comma- or semicolon-delimited files, either decimal convention, and non-US code formats. But BenchForge has to know which of your payer segments actually move when that schedule moves — and by default it guesses from the payer's name, looking for "Medicare". That finds nothing outside the US.
So on each assay's Economics tab, set "Moves with the fee schedule" to Yes on the segment that follows your schedule (the GKV rate, the NABM tariff). It is a one-time setting per segment. Until you do, affected assays are listed as not assessable rather than silently scored zero — the per-code comparison works either way.
Billing. If you're VAT- or GST-registered, checkout collects your business tax ID and legal business name and puts both on every invoice — enter your VAT number at the "I'm a business" prompt. We validate EU, UK and Australian numbers against the relevant government database.
And one thing that genuinely does not port. Grading past decisions against what you were actually paid depends on a remittance file. The US X12 835 is the format we parse today. Every reimbursement system produces an equivalent — a German quarterly settlement, a French return file — but we do not read them yet, so an ex-US workspace runs without the actuals loop until one is added for your market.
Yes, per lab. AI-assisted SOP import and column mapping are opt-in per use, and the lab can disable them entirely in Settings — today any member with edit access can flip that switch (an admin-only restriction is on the roadmap, disclosed in the IT packet). The switch itself is enforced server-side and fails closed, so even a direct request that bypasses the UI is refused. Only text you provide is ever sent to the AI sub-processor; PDF and image files never are, and the text is screened for identifiers first. Everything else in BenchForge is deterministic, in-browser modeling.
Yes — your model is yours. Settings gives you a complete, open JSON export of the entire workspace (every assay, resource, schedule, and period), readable without us. The Leadership Summary exports as a finance-ready CSV and a board-ready PDF, and share links give a scoped, revocable read-only view. There is no lock-in by design.
The fair version of this question is "what am I left holding", and the answer is: everything, in a form you can use without us.
Your whole workspace exports to a single file on demand — not a report, the complete model: every assay, every input, every locked baseline and committed decision. The formula sheet documents every calculation the product runs, with worked examples, and the model is deterministic: the same inputs always produce the same figures. Between those two things, a competent analyst can reproduce your numbers in a spreadsheet without us existing.
We would rather you never need that. But a lab planning three years out is right to ask, and "trust us" is not an answer we're entitled to give.
Your license ends and you keep an export window: you may export your data for 30 days after termination or account closure, after which we may delete or de-identify it per the Privacy Policy. Take the full JSON export before you go — it's the complete model, and it's yours.