Platform Platform
System
ConceptsEnginePolicy as codeDeclarationsSafe changeGatewaysIntegrationsObservabilityAdministrationSecurityHuman reviewAudit and evidenceData retentionSecrets and data classification
Controls
Registries and documentationAuthentication and authorizationInjection detectionData redactionCode fingerprintingRole and judge checksContent classificationSpend and loop limitsBusiness rules
Solutions Solutions
By what you do
Sell into the enterpriseControl the AI you run
By industry
Financial servicesDigital assetsInsuranceHealthcareLegalUser-generated content
By discipline
AI governanceTrust and safetyRisk and compliance
Cases Cases Embedded control planeSource-code leakTrading agents over MCPLive firehoseRefund assistant
Compare Compare LiteLLMNVIDIA NeMo GuardrailsOPAROOSTAgent Governance Toolkit
Resources Resources
Guides
Enterprise review questionsPrompt injectionAgent and control layerAgent architecturesDecision system mapAI control maturity model
Standards
Standards OWASP Agent Control StandardEU AI ActPMI AI standardNIST AI RMFERC-8004
Book a demo
Solutions · By industry

PHI does not leave. The assistant knows what it may not say.

Two questions decide whether AI goes live in a health setting: where the patient data goes, and what happens when the model is confidently wrong.

Building AI for hospitals and payers rather than running one? Yours is sell into the enterprise.

What your compliance office asks, and what answers it

The questionThe answer here
Where does PHI go?It stays in your environment and never reaches us, the company behind Swiftward. Where you route a prompt to a hosted model, redaction runs before it leaves.
Will you sign a BAA?Yes.
Minimum necessary: does the model see more than it needs?A rule strips fields before the prompt leaves and restores them in the reply. The model sees placeholders.
Which de-identification method?Safe Harbor is a rule you can read, not a model you have to trust: most of its identifiers already have a detector, and you add the rest. For Expert Determination, your expert decides and we hold the evidence they base it on.
If something did get out, would you know?The record shows what was redacted and what was not, per decision. That is what a breach assessment needs.

When allowed fields together identify a patient

Safe Harbor strips eighteen identifiers. A rare diagnosis, the year of birth and the first three digits of a ZIP code may all stay, and together they can identify the patient. A scanner that reads one field at a time passes that prompt. A rule sees the whole request, so it can act on the combination.

The redaction layer can also run named-entity recognition, which finds names, places, dates, identifiers and medical license numbers in free text. What the redaction layer recognizes.

When the model is confidently wrong

A clinical assistant that answers with certainty and no source is more dangerous than one that says nothing.

A rule can require a citation — and, where you supply a lookup function, check that it is found in the source you point it at. It can check the answer against the role the assistant was given, and send anything that fails to a clinician rather than to the patient.

How that check works: role and judge checks. Where the handover goes: human review.

Fitness, coaching and mental health count too

They hold health data without being clinical, and their users assume the same care. The controls are the same, even where the regulator is different.

Where your regulator goes further than HIPAA

42 CFR Part 2. Substance use disorder records need stricter handling than the rest of PHI. Stored as fields, they are classified once, and the classification holds on every screen, export and forwarded event. Inside a prompt or a tool response, they get their own detection and redaction rules. You declare both.

The clinical boundary. Wherever you and your regulatory counsel draw the line between support and clinical decision support, a rule enforces it on every request. The assistant does not produce a diagnosis, a dose, or a recommendation you have not authorized.

Related: AI governance · Risk and compliance
Book a demo