Skip to content
Architecture

One sealed stack. In a cloud you own.

One sealed stack. In a cloud you own.

Not a feature list. Each layer exists to prevent a specific failure that happens when AI enters a business whose data is protected — and together they answer only three questions.

The stack, top to bottom

your project boundary

The switchin your hands
The runtimewhat each agent may do
The verifiereach claim against its source
Your projectyour cloud, your billing

We operate the software. We are never in the data path.

01

Where does it run?

In your project, with no copy on our side and no key left behind.

The failure this prevents: a vendor holding a copy. Once the data sits with them, every assurance is policy — and every breach on their side is a breach on yours.

A project in your name

The project is in your name, on your billing, in the region you choose. We operate the software — your data never passes through us.

Our access is temporary

It expires on its own, and it is written in your own log. The keys the system does use are yours — and you switch them off without us.

What leaves

Nothing comes back to us — we have nowhere for it to go. The only thing that leaves is an alert to your own team, to a destination you choose, with personal details removed first.

02

What is it allowed to say?

Only what rests on a document your clinic has opened to it.

The failure this prevents: a convincing answer with no source. A model that phrases well sounds right exactly when it is wrong — and that alone is why tools like this don't enter regulated businesses.

Permission comes first

The agent can only draw on the documents your clinic has opened to it. That limit is applied before the search runs — not by filtering the answer afterwards.

Superseded versions are out of play

The answer rests on the live document, not the one that used to be right.

One unsupported claim rejects the answer

Not the sentence — the whole answer. What comes back is either “this isn't in your documents”, or an answer marked unverified — never a guess dressed as fact.

03

Who stays in control?

You do — including the ability to end it without asking us.

The failure this prevents: an exit that depends on the vendor. If ending the relationship needs our cooperation, you don't hold the system — you rent it.

Every action has a limit

Everything the agent can do is defined in advance, with its own limits — and permission is checked by the system, not by the model.

What doesn't close goes to a person

With full context, and it stays open until someone takes it — whether or not the alert arrives.

The record and the switch are yours

Every action is written in your project and stays there. At handover you remove our access yourselves — in your own console, without asking us.

In depth

The verifier.The layer you can test yourselves.

Anyone can promise “it doesn't invent”. What no one can promise without building it is a mechanism that rejects a whole answer over a single claim. That is what this layer does, and it is what turns the refusal into a feature rather than a fault.

Every answer is broken into claims

It isn't checked as a paragraph. Each claim is checked on its own against the source it came from.

The checker is not the writer

In the console, a separate model checks the answer before you see it. Messages to patients are checked against your own records and settings before they go out. A model checking itself is not a check — it is the same bias twice.

No free retries

A regeneration is a fresh chance to be wrong, not a second chance to be right.

And what it doesn't catch

Verification checks that every claim rests on your documents. It cannot make a wrong document right — that is a separate job, showing you where your own records disagree with each other. A tool that promises more than this is promising.

One stack,one decision.

Not one layer here was chosen because it's impressive. Each exists because without it there's a failure you can't live with when the data is protected by law. Together they say one thing: the agent works in your project, and after handover we hold no permission to reach the data.

Want to see how this sits in your cloud?

Book a demo