Platform · Data Privacy Gateway

Run cloud AI on real clinical data. Without the PHI ever leaving the building.

An on-premises tokenisation appliance that lets health systems run cloud analytics and AI on complete clinical data, while every patient identity stays inside the firewall.

PHI never leaves your network · FHIR R4 native · mTLS re-identification, you hold the key

Tokenised before it crosses the firewall

Complete clinical data in the cloud. Zero identities.

Data Privacy Gateway flow: clinical source inside the firewall, DPG appliance tokenises every identifier, cloud AI sees tokens only
Real identities live only in your on-prem vault, revealed on demand over an authenticated mTLS callback, never cached. You hold the key.

The problem

The barrier was never the model.

Health systems hold the most valuable clinical data in the world and can't use most of it. The moment PHI leaves the building for a cloud model, it becomes a breach surface, a BAA liability, and a sub-processor risk no contract fully covers.

So the data stays locked down, AI projects stall in legal review, and staff quietly paste patient details into consumer chatbots anyway. It is the identity attached to the record.

What DPG does

DPG removes the trade-off.

It tokenises every identifier on-premises, at the source, before a single byte leaves your network. The cloud and the AI see complete, structured, FHIR-native clinical data. They never see a name, an MRN, or a date of birth.

  • HMAC-SHA256, deterministic tokens
  • Real identities stay in your on-prem vault
  • Revealed only over authenticated mTLS, never cached

The cloud cannot leak PHI it never receives.

How DPG compares

One category, four very different answers.

Hosted privacy vault
Skyflow-type
Linkage network
Datavant-type
LLM redaction
Prompt proxy
IASORA DPG
Where PHI livesIn the vendor's hosted vaultTokenised for movement across a networkPasses through a gatewayInside your building, always
Primary jobIsolate PII for app workflowsLink datasets for research and RWDFilter prompts at the gatewayTokenise full clinical data at source for cloud AI
FHIR nativeHorizontal, not FHIR-ledIdentifier-focusedNoFHIR R4 native
Utility after privacyHigh, but vendor-heldLinkage onlyLossy redactionFull structured clinical data, deterministic tokens
Re-identificationVendor-mediatedBilateral token transformNot applicablemTLS callback to your appliance, you hold the key

Why it's different

Privacy as architecture, not a promise.

PII never leaves your network

It is structurally impossible for the cloud to hold patient identities. They were tokenised before they crossed your firewall.

Tokenised data stays useful

Deterministic tokens mean the same patient gets the same token everywhere. Longitudinal records, analytics, and linking all work. You lose the PII, not the insight.

Built for the security team

mTLS on every resolution call. Full audit trail. No PII in logs, ever. A pluggable encrypted vault you own.

The AI angle

Give clinicians a sanctioned path, and end shadow AI.

Run cloud AI on real data

Your models get complete clinical context. They never get an identity.

End shadow AI

Give clinicians a sanctioned path so they stop pasting PHI into consumer tools.

Deploy in weeks

Keep identity behind the firewall, as a product, FHIR-native. The pattern the most cautious health systems already chose.

What it means for you

Provable privacy, for every seat.

CISO

Nothing to breach in the cloud

  • The cloud never receives an identity, so there is none to expose
  • No PII in logs, ever
  • mTLS on every resolution call
CIO

Adopt cloud AI now

  • No multi-year data-governance project
  • FHIR R4 native, deploy in weeks
  • Cloud-scale analytics on real data
Clinicians & Analysts

Full context, when authorised

  • Full clinical context
  • Live patient lookups
  • Resolved only when authorised

De-identify by design

Analyse without compromise. Resolve only when authorised.

DPG is your on-ramp to the IASORA platform: cloud-scale clinical analytics, AI, and interoperability, on a foundation where privacy is provable, not promised.