Platform · Data Privacy Gateway
Run cloud AI on real clinical data. Without the PHI ever leaving the building.
An on-premises tokenisation appliance that lets health systems run cloud analytics and AI on complete clinical data, while every patient identity stays inside the firewall.
PHI never leaves your network · FHIR R4 native · mTLS re-identification, you hold the key
Tokenised before it crosses the firewall
Complete clinical data in the cloud. Zero identities.
The problem
The barrier was never the model.
Health systems hold the most valuable clinical data in the world and can't use most of it. The moment PHI leaves the building for a cloud model, it becomes a breach surface, a BAA liability, and a sub-processor risk no contract fully covers.
So the data stays locked down, AI projects stall in legal review, and staff quietly paste patient details into consumer chatbots anyway. It is the identity attached to the record.
What DPG does
DPG removes the trade-off.
It tokenises every identifier on-premises, at the source, before a single byte leaves your network. The cloud and the AI see complete, structured, FHIR-native clinical data. They never see a name, an MRN, or a date of birth.
- HMAC-SHA256, deterministic tokens
- Real identities stay in your on-prem vault
- Revealed only over authenticated mTLS, never cached
The cloud cannot leak PHI it never receives.
How DPG compares
One category, four very different answers.
| Hosted privacy vault Skyflow-type | Linkage network Datavant-type | LLM redaction Prompt proxy | IASORA DPG | |
|---|---|---|---|---|
| Where PHI lives | In the vendor's hosted vault | Tokenised for movement across a network | Passes through a gateway | Inside your building, always |
| Primary job | Isolate PII for app workflows | Link datasets for research and RWD | Filter prompts at the gateway | Tokenise full clinical data at source for cloud AI |
| FHIR native | Horizontal, not FHIR-led | Identifier-focused | No | FHIR R4 native |
| Utility after privacy | High, but vendor-held | Linkage only | Lossy redaction | Full structured clinical data, deterministic tokens |
| Re-identification | Vendor-mediated | Bilateral token transform | Not applicable | mTLS callback to your appliance, you hold the key |
Why it's different
Privacy as architecture, not a promise.
PII never leaves your network
It is structurally impossible for the cloud to hold patient identities. They were tokenised before they crossed your firewall.
Tokenised data stays useful
Deterministic tokens mean the same patient gets the same token everywhere. Longitudinal records, analytics, and linking all work. You lose the PII, not the insight.
Built for the security team
mTLS on every resolution call. Full audit trail. No PII in logs, ever. A pluggable encrypted vault you own.
The AI angle
Give clinicians a sanctioned path, and end shadow AI.
Run cloud AI on real data
Your models get complete clinical context. They never get an identity.
End shadow AI
Give clinicians a sanctioned path so they stop pasting PHI into consumer tools.
Deploy in weeks
Keep identity behind the firewall, as a product, FHIR-native. The pattern the most cautious health systems already chose.
What it means for you
Provable privacy, for every seat.
Nothing to breach in the cloud
- The cloud never receives an identity, so there is none to expose
- No PII in logs, ever
- mTLS on every resolution call
Adopt cloud AI now
- No multi-year data-governance project
- FHIR R4 native, deploy in weeks
- Cloud-scale analytics on real data
Full context, when authorised
- Full clinical context
- Live patient lookups
- Resolved only when authorised
De-identify by design
Analyse without compromise. Resolve only when authorised.
DPG is your on-ramp to the IASORA platform: cloud-scale clinical analytics, AI, and interoperability, on a foundation where privacy is provable, not promised.