Sovereign by design, enterprise by default
Governed before it is clinical.
Sovereign clinical AI has to satisfy privacy, security, and clinical governance before it earns a place in a workflow. This is the posture we design to, and the documentation we bring to a review.
The safety property built into the platform, not a setting on top of it. A qualified human holds the judgement and the accountability: every model, agent, and workflow is designed to inform that person and stop at them.
A clinician decides
The system surfaces evidence, risk, and reasoning. It does not order, prescribe, or act on a patient. Every clinically consequential step waits on a named person with the authority to take it.
Approval before action
Anything sensitive routes to explicit human approval before it takes effect. The approval gate is enforced in the platform itself, not left to policy documents or user discipline.
Reasoning shown, not hidden
Every output carries what it drew on, what it was missing, and how it was formed, so the reviewing clinician can accept, question, or reject it on the evidence rather than on trust.
Accountability stays human
The operator, the custodian, the key-holder, and the approver are the institution's own people. Clinical accountability is never transferred to a model or to us.
Sovereign by design, enterprise by default
Security posture
Controls the institution can verify
01 / Encryption
Encryption at rest and in transit across every tier of the deployment.
02 / Identity
SSO and SAML identity integration with the institution's existing directory.
03 / Access
Role-based access, scoped to the unit and the function, with multi-factor authentication.
04 / Audit
A complete audit trail on every interaction, retained for institutional review.
Privacy by design
Designed for the law it operates under
Designed to operate within Canadian health-privacy law: PIPEDA and the applicable provincial health-information act, with the health authority as custodian and every AI response generated inside its own boundary.
CELSUS holds no patient data. The bedside platform deploys single-tenant inside the institution's boundary, with zero data egress.
Responsible AI
Commitments we hold to
- Clinician oversight always
- No autonomous diagnosis
- Shadow-mode-first validation before any clinical workflow expands
- Continuous evaluation against the institution's own criteria
Documentation available under NDA
- Architecture overview
- Security whitepaper
- Deployment model
- Privacy-impact-assessment support
- Evaluation methodology
Evaluation
Reviewed on the institution's terms
- Scoped use case, defined success criteria, defined review point
- Shadow mode first, observing and logging only
- Results reviewed against the site's own criteria before expansion
- Expansion by invitation, on the site's timeline
Technical briefings are held under NDA. Request one below.
