August 12, 2026 · 6 min read
Let software read the certificate. Do not let it own the date.
Speed without a signature is how a swapped year becomes official. The useful split is simple: vision fills the form. A person you trust accepts it.

Trust
Extraction is a draft. Confirmation is the record.
Clinics are right to be suspicious of a model that “understands” a DEA certificate. They are also tired of typing every field. Both instincts are correct. The product that deserves trust is the one that shows the file next to the fields and waits.
A swapped digit in a year is not a cute AI mistake. It is a calendar that will be quiet until it is not. Protective software is slow in one place: the moment a human says yes.
What is worth extracting
- Named entity as printed
- Issuing authority
- Document type
- Expiration date on this file
What is not worth pretending to extract: legal interpretation, tail coverage, whether this CLIA type is sufficient, whether the DEA address matches the site. Those stay with directors, brokers, and counsel. The instrument reads the paper. People still run the facility.
AI fills the form. Your team signs off. That sentence is the product.
Review has to be short enough to finish
If confirmation is a project, people will skip it and the calendar will be fiction. Keep the screen to the file and the four fields. Make it possible between patients. Then the director can trust the date because someone actually looked.
Questions
Will CalSafe change a date on its own?
No. Extraction fills a form. The calendar does not move until someone on your team accepts the fields.
What if the scan is wrong?
Correct it in review. That is the point of the step. A misread stamp or a two-sided card should never become the official expiry.