The AI reasons; the physician decides.
Every output passes through a must-review-before-final gate. Clinicians review and sign every artifact before it becomes part of the chart. AB 489 compliance is the substrate, not a footnote.
ChironAI is built for the regulatory realities of healthcare. The pages below document the frameworks we comply with, the controls we operate, the data we never touch, and the disclosures we are deliberate about. Designed to be the one URL a procurement officer can send to their CISO with confidence.
Every Trust Center page is print-friendly. Procurement teams routinely attach these documents to RFP responses.
Regulatory frameworks ChironAI is engineered around — California AB 489 (AI as decision-support, not clinician), SB 1120 (physician decision authority), AB 3030 (generative AI disclosure), AB 375 CCPA/CPRA Automated Decision-Making Technology, HIPAA-aligned controls, GDPR and UK GDPR posture.
Encryption, audit chain, access control256-bit encryption at rest and in transit. Tamper-evident HMAC + previous-hash audit chain. SHA-256 document signature integrity. Fine-grained clinical RBAC. Multi-tenant isolation enforced by tenant ID guards. MFA on staff accounts. SOC 2 audit-ready controls; formal audit pathway evaluation underway.
No customer data in training, by constructionEve-Genesis (Clinical Edition) is 100% synthetic by construction. No customer data, no patient data, and no protected health information enters our training pipeline — ever, by architectural property. Data residency commitments by region. Retention policies per data class. BAA available for institutional customers.
FDA SaMD posture, audit status, jurisdictionalWhere we are deliberately silent or not yet certified — honest framing rather than overclaim. FDA SaMD pathway evaluation, SOC 2 and ISO 27001 current status, audit firm relationships, jurisdictional disclosures across the operating regions.
The pages below are built for the enterprise security-diligence and SOC 2 audit process. They map our controls to the Trust Services Criteria, list our subprocessors, document how we respond to incidents, and set out the availability posture — the material a CISO or auditor asks for before a formal report exists.
Our controls mapped to the five SOC 2 Trust Services Criteria — Security (Common Criteria), Availability, Confidentiality, Processing Integrity, and Privacy. Built to accelerate a security questionnaire or auditor readiness review. SOC 2 Type 1/2 evaluation underway; not yet certified. Detailed controls-mapping document available to institutional customers under NDA.
Who touches the service, and on what termsThe short list of third parties that process data on our behalf — Microsoft Azure under Microsoft’s HIPAA BAA for compute and storage, frontier reasoning model provider(s) under enterprise contract with no PHI training or retention, and Microsoft Clarity on the marketing site only, consent-gated. Updates posted here.
Detection → containment → recovery → reviewThe incident-response lifecycle and how breach notification is handled — consistent with HIPAA/HITECH and applicable state law, routed through institutional Business Associate Agreements. Security contact and vulnerability-disclosure channel included.
Blue-green, canary, continuous-restoreAzure Container Apps with health probes, blue-green and canary deployments, continuous-restore PostgreSQL backups, and RTO/RPO documented per institutional deployment. Availability is a per-deployment commitment, not a single public uptime number.
Institutional customers running formal vendor diligence can request the artifacts below under NDA. We list only what we actually provide — where an artifact does not yet exist, we say so rather than imply one. We do not currently maintain a completed CAIQ or SIG questionnaire; we answer security-questionnaire content directly from the controls-mapping document and welcome a customer’s own format.
Every output passes through a must-review-before-final gate. Clinicians review and sign every artifact before it becomes part of the chart. AB 489 compliance is the substrate, not a footnote.
Eve-Genesis (Clinical Edition), our proprietary training corpus, is 100% synthetic. The architecture cannot leak what is not present. This is an architectural property, not a policy promise.
Tamper-evident HMAC + previous-hash audit chain on every clinical action. SHA-256 signature integrity on every signed document. Versioned, traceable, reviewable end to end.
Free-form interfaces are incompatible with the auditability requirements of regulated industries. ChironAI is structured-workflow by design — evidence presented openly, reasoning visible at every step, confidence calibrated, every source cited.
You cannot train bias out of a model; you can only separate the reasoning from the knowledge from the jurisdiction, so the bias becomes something you can read, audit, and govern.
Algorithmic bias in clinical decision support is not hypothetical — risk scores that under-serve the patients who need care most are among the best-documented failures in health AI. It happens because a single model learns the inequities of the historical record in the same weights that carry its competence; you cannot scrub one without disturbing the other. ChironAI does not try. It separates the three things a single model fuses.
The reasoning is trained on logic, not on outcomes. The clinical reasoner learns the modes of diagnosis — abductive, analogical — from the structure of inference itself, on Eve-Genesis (Clinical Edition) synthetic data. It is never shown a record of who historically received which care, so there is no demographic distribution to inherit.
The knowledge is rented and bounded. Frontier models are consulted for narrow sub-questions — a drug interaction, a guideline lookup — inside a fence the reasoner draws. They answer; they never frame the case.
The standard of care is written down. The guideline in force in this health system, this region, this population is carried as a plain-language instruction, not baked into a model. A clinician can read it, challenge it, and change it for the next care setting without retraining anything — and when a result is wrong, point to the layer that produced it. The assumption is a sentence, not a secret — the full argument.
Reach our security and compliance team directly. We respond to procurement and security-due-diligence inquiries within two business days.
Start a conversation →Agentic AI Operating Systems sit between low-agency helpers (Copilots, RAG chatbots) and high-agency autonomous agents (auto-GPT-shaped systems). They act, but the discipline’s expert remains the decider on every consequential output.
An Agentic AI Operating System — a Digital Employee that does the work of cognition alongside the discipline’s human workforce.
Bounded agency. The OS acts within delegated authority. The human remains the consequential decider.
Because the reasoning is trustworthy. Reasoning the team trusts because the team trained it.
Eve-Genesis. Reasoning-style conditioning. The reasoner is shaped in the discipline’s cognitive operations, not glued onto a generalist model.
The AI reasons. The clinician decides.
The clinician remains the consequential decider. The platform does the work of cognition that supports the decision. The line between agency and autonomy is drawn there, on purpose.
Constructs differentials, surfaces evidence, drafts documentation, flags red flags, queries the literature, suggests next clinical actions.
Orders the workup, makes the diagnosis, signs the chart, prescribes, communicates with the patient, accepts the clinical responsibility.
The market sorts AI products into two categories. Helpers — Copilots, ChatGPT plugins, RAG chatbots — are useful but not products in the institutional sense. They assist; they do not run anything. Autonomous agents — auto-GPT-shaped systems, fully self-directing — are technologically impressive but procurement-unsafe in regulated verticals. The liability surface is unacceptable. The institutional buyer cannot deploy them.
MindHYVE sits in a third position. Bounded agency. Enough agency to be a real product — a Digital Employee that does the work of cognition. Bounded enough to be safe for deployment in healthcare, education, law, theology — verticals where autonomy is structurally unacceptable and helpers are inadequate to the job.
That third position is structurally hard to take. It requires reasoning the institution actually trusts. Eve-Genesis is what makes the trust earnable. Without the trust substrate, an institution can deploy a helper but not an operator. With it, an institution can deploy an operator that remains under human consequential control.
Tell us the workflow you want to see and who needs to be in the room. A member of our clinical and engineering team replies within two business days to arrange it — a real person, not a sequence.
Talk to our team →What happens after you send it
Prefer to talk now? +1 (949) 200-8668, or email hello@mindhyve.ai.