Sovereign by design, enterprise by default
Publicly stewarded care, province by province.
The top tier of the stack is a province-governed hub, aligned to the authorities that already hold accountability for patient information. Institutions keep custody of that data locally and contribute de-identified, governed data upward only when authorized, never automatically, never to a third party.
Engineered for the standards Canadian healthcare runs on
- HL7 FHIR
- SNOMED CT
- LOINC
- ICD-10-CA
- Drug identification numbers (DIN)
Sovereign by design, enterprise by default
Tiers in Canada
Bedside · unit · hospital · province
Province-governed AI hub
A sovereign hub serving the health authorities of one province, governed under provincial health-information law and interconnect-ready if national federation is ever required.
Health authority and hospital infrastructure
Compute inside the facility, operated by the authority's existing technology teams on a segmented network with no inbound internet exposure.
Unit and department nodes
Local nodes running small and large language models we deploy and govern, sized to a clinical unit or department. Compact workstations and rack nodes rather than construction projects.
Edge AI at the point of care
Sub-second analysis at the bed space, with device-data gateways feeding the unit tier.
Governance
Designed for the Canadian legal environment
- Designed to align with PIPEDA and provincial health-information acts
- Privacy-impact-assessment support as part of the deployment package
- Data residency in Canada, with processing inside the institution
- Bilingual (English/French) content pathway where clinical content is served
- Health-authority-held keys, policies, and audit records
Procurement reality
One unit first, then the authority
- A scoped clinical use case in a single unit, governed from day one
- Evaluation against the site's own criteria before any expansion
- Institutional infrastructure economics rather than per-user pricing
- Expansion by invitation, on the authority's timeline
Governance checklist
How a Canadian deployment is governed
The four areas your privacy, security, and clinical teams review first. Bring this to a technical briefing and mark it against your authority’s own criteria.
Authority
A public health authority is legally accountable for the patient information and for the system that touches it.
- Named accountable executive and clinical sponsor inside the authority
- Authority-approved use case, scoped to one unit before anything expands
- Provincial privacy office engaged before the first clinical question
- Privacy-impact-assessment support supplied as part of the deployment package
Residency and processing
Patient information stays with the organization legally responsible for it; no third-party cloud service processes it.
- Compute runs on premises, inside the authority's network boundary
- Data residency in Canada, with no egress for clinical processing
- Provincial contribution only when authorized, de-identified, and governed, never automatic
- Designed to align with PIPEDA and provincial health-information acts
Identity and access
The authority's existing identity system remains the single source of truth for who may see what.
- SSO/SAML against the authority's identity provider
- Role-based access mapped to existing clinical roles
- Encryption at rest and in transit, with authority-held keys
- Access reviews run on the authority's own cycle
Clinical oversight
Clinicians decide; the system informs. No workflow expands without evidence reviewed by the site.
- Shadow-mode first, observing and logging only, before any workflow change
- No autonomous diagnosis, and clinician oversight at every step
- Complete audit trail on every interaction, held by the authority
- Bilingual (English/French) content pathway where clinical content is served
- Expansion by invitation, on the authority's timeline
Why this shape
Public stewardship sets the boundaries
01 / Local by default
Patient information stays with the organization legally responsible for it. Clinical AI responses are generated inside the institution.
02 / Provincial when authorized
De-identified, governed contributions support model development under provincial authority, never as an automatic transfer.
03 / National when required
The architecture is interconnect-ready, so provincial capacity can join a national fabric without redesign.
04 / No third-party control
No outside operator, custodian, key-holder, or licensor controls the system. Hardware runs on premises under institutional control.
Where to start
Products, as they land in a Canadian health authority
SALVEA.
The hospital’s control layer for AI: one governed runtime for every assistant, agent, and workflow, deployed single-tenant inside the institution’s boundary: zero data egress, the clinician’s final say.
Explore SALVEA →TRIMPACT
The bedside critical-care platform, deployed inside the health authority's network with keys, policies, and audit held locally.
Explore →CELSUS
Governed clinical reference with a bilingual (English/French) content pathway and pharmacy-controlled content per authority.
Explore →CECI
Grounded answering over the authority's approved library, with a citation on every answer and no source found when the library is silent.
Explore →MINIM
Ambient documentation drafted on authority compute, signed by a clinician before anything reaches the record.
Explore →FIGURA
Contact-free bedside sensing as geometry only, with no likeness produced and no imagery stored inside the authority.
Explore →CHICKADEE
The family app, keeping families connected to their baby's journey across the admission.
Explore →Request a technical briefing. · held under NDA
