One sealed stack. In a cloud you own.

Not a feature list. Each layer exists to prevent a specific failure that happens when AI enters a business whose data is protected — and together they answer only three questions.
The stack, top to bottom
your project boundary
We operate the software. We are never in the data path.
Where does it run?
In your project, with no copy on our side and no key left behind.
The failure this prevents: a vendor holding a copy. Once the data sits with them, every assurance is policy — and every breach on their side is a breach on yours.
A project in your name
The project is in your name, on your billing, in the region you choose. We operate the software — your data never passes through us.
Our access is temporary
It expires on its own, and it is written in your own log. The keys the system does use are yours — and you switch them off without us.
What leaves
Nothing comes back to us — we have nowhere for it to go. The only thing that leaves is an alert to your own team, to a destination you choose, with personal details removed first.
What is it allowed to say?
Only what rests on a document your clinic has opened to it.
The failure this prevents: a convincing answer with no source. A model that phrases well sounds right exactly when it is wrong — and that alone is why tools like this don't enter regulated businesses.
Permission comes first
The agent can only draw on the documents your clinic has opened to it. That limit is applied before the search runs — not by filtering the answer afterwards.
Superseded versions are out of play
The answer rests on the live document, not the one that used to be right.
One unsupported claim rejects the answer
Not the sentence — the whole answer. What comes back is either “this isn't in your documents”, or an answer marked unverified — never a guess dressed as fact.
Who stays in control?
You do — including the ability to end it without asking us.
The failure this prevents: an exit that depends on the vendor. If ending the relationship needs our cooperation, you don't hold the system — you rent it.
Every action has a limit
Everything the agent can do is defined in advance, with its own limits — and permission is checked by the system, not by the model.
What doesn't close goes to a person
With full context, and it stays open until someone takes it — whether or not the alert arrives.
The record and the switch are yours
Every action is written in your project and stays there. At handover you remove our access yourselves — in your own console, without asking us.
In depth
The verifier.The layer you can test yourselves.
Anyone can promise “it doesn't invent”. What no one can promise without building it is a mechanism that rejects a whole answer over a single claim. That is what this layer does, and it is what turns the refusal into a feature rather than a fault.
Every answer is broken into claims
It isn't checked as a paragraph. Each claim is checked on its own against the source it came from.
The checker is not the writer
In the console, a separate model checks the answer before you see it. Messages to patients are checked against your own records and settings before they go out. A model checking itself is not a check — it is the same bias twice.
No free retries
A regeneration is a fresh chance to be wrong, not a second chance to be right.
And what it doesn't catch
Verification checks that every claim rests on your documents. It cannot make a wrong document right — that is a separate job, showing you where your own records disagree with each other. A tool that promises more than this is promising.
One stack,one decision.
Not one layer here was chosen because it's impressive. Each exists because without it there's a failure you can't live with when the data is protected by law. Together they say one thing: the agent works in your project, and after handover we hold no permission to reach the data.