The HIPAA-compliant AI platformfor regulated industries

HIPAA-compliant AI for healthcare
and regulated industries.

Chat, workflows, APIs, agents, and bespoke internal tools — all on one signed audit chain, one BAA, and one PHI-aware policy layer.

HASP CONTROL PLANEEvery request, signed off.One control plane. All four surfaces.▼ incoming requestChat· clinicianClinical note · summaryIdentityPHI HandlingPolicyAuthorizationAudit▸ request · req_001Clinical note · summarycaller⋯ awaitingpayload⋯ awaitingpolicy⋯ awaitingscope⋯ awaitingsignature⋯ awaiting▌ signed chained25519 · append-only
BAA included Signed audit trail PHI under your policy No training on your data
Compliance · frameworks we ship under
Independently validated HIPAA BAA on every paid plan
Report under NDA SOC 2 Type II · attested
Certification in progress HITRUST CSF e1
EU + UK GDPR Art. 17 · 20 · 30
Active CCPA / CPRA California
Active + CPPA-ready PIPEDA Canada
Two paths into the platform

Start with the path that fits your team.

● For organizations

Use HASP directly

Deploy compliant AI for your organization without stitching together models, workflow tools, and audit systems.

  • AI assistant for regulated work
  • Document analysis and summarization
  • Workflow automation
  • Bespoke internal tools
  • One BAA, one audit trail, one bill
Explore Platform →
● For developers & platform teams

Build on HASP

Use HASP as the governed foundation for regulated AI products, agents, and workflows.

  • Public API
  • Agent SDK
  • Agent identity and delegated authorization
  • PHI handling
  • Policy enforcement and signed audit events
Explore Developers →
The platform

One platform. Four ways to use it. One audit trail across all of them.

Whether your team starts with chat, internal tools, APIs, or agents, every surface runs through the same governed system.

01 Surface

Chat & documents

Compliant chat that can read your documents — uploads, search, citations. The familiar chat shape, with every prompt and response logged and signed. Drop-in productivity from day one.

Learn more →
02 ★ Build on it

Studio

An AI-powered builder for the tools your team keeps asking IT to ship. Describe the workflow — intake, triage, prior-auth, care-coordination, billing scrub — and HASP builds it. Live in your environment in days, with the BAA, audit trail, and PHI controls already in place.

See how Studio works →
03 Surface

Public API

The same AI capabilities, callable from your software. Plug it into your EHR, your intake workflow, your patient portal — same BAA, same audit trail.

Learn more →
04 Surface

Agent SDK

Connect external agents and automation pipelines. Every tool invocation is authorized, identity-scoped, and recorded to the signed audit chain.

Explore agents →
The model layer

Built on every leading model. Never locked to one.

Most teams build against a single AI provider — and inherit that provider's outages and that provider's pricing. HASP routes across multiple leading providers under one BAA, so neither becomes your problem.

01

Redundancy through an outage

Every frontier provider has incidents. When your default model is unavailable, HASP routes the request to a healthy model on another provider — automatically, no admin paged. The work doesn't stop.

02

Never locked to one vendor

When a different provider ships a better model, switching your org's default is a setting — not a new contract, security review, or integration sprint. The provider underneath is a routing detail.

03

Pricing leverage

If one provider's pricing moves the wrong way, you're not trapped. It's one bill with one price unit — no per-provider invoices — so moving workloads to a better-priced model is a policy decision, not a re-architecture.

04

Right model for the task

Providers lead at different things. Run a lightweight model for high-volume classification, a high-capability model for hard reasoning — your choice, per workload, on one bill.

See every supported model →
▌ Audit & Trust

Trust that
can be verified.

HASP records sensitive AI activity on a signed audit chain, enforces policy before action, and handles PHI inside the governed platform instead of leaving every team to stitch controls together.

Every surface. Every action. One verifiable record.

Open the Trust Center →
● 01

One BAA, every surface

Put AI in front of regulated work with the paperwork already handled. One BAA covers Assistant, Studio, API, and Agent SDK — sign in-app, unlock PHI mode.

● 02

PHI on your terms

Send PHI to the model under your BAA, or turn on redaction before it leaves your environment. Your policy, your choice, per org.

● 03

Policy enforced before action

Nothing your policy forbids reaches a model or a tool. Rules are checked at the gateway before each call proceeds.

● 04

An audit trail that holds up

When an auditor asks who did what, when — you have an answer that holds up. Hash-chained, Ed25519 signed, RFC 3161 anchored, and verifiable on their machine in one command: npx @usehasp/verify. No vendor in the loop.

● 05

Never used for training

Your data is never used to train AI models — ours or anyone's. That commitment is written into our privacy policy.

● 06

Compliance your reviewers accept

One posture that answers the security questionnaire: HIPAA, SOC 2, HITRUST, GDPR, CCPA, PIPEDA. AOCs available under NDA.

Build your own

The tools you've
stopped asking IT for.
Describe them. Ship them.

Every regulated team has a list — the triage queue, the intake form, the tracker that never made a vendor's roadmap. Studio builds them from a plain-language description, with the BAA, policy enforcement, and audit trail already in place.

The right person to design your triage queue is the person triaging. The right person to design your matter-intake form is the paralegal running intake. We think every regulated team ends up with a portfolio of small, sharp tools like these — built by them, owned by them, audited by default.

That portfolio runs on HASP.

● The math, briefly
Generic SaaS subscription $80–400 / user / mo
Implementation + customization months
Built for the average customer not you
Audit-readiness separate vendor
● Build it in HASP instead
One platform fee + published usage rates no surprises
Time to first app days, not quarters
Fits your workflow you described it
Audit-readiness baked in
What you could build
● Studio · template walk-through

Scores inbound patients on the urgency signals your team actually uses — not the ones a generic vendor decided to ship — and routes each one with the reasoning on the record.

Patient triage queue For practice owners
● Studio · template walk-through

Drafts the clinical justification, attaches the right history, and flags missing fields before the form goes out.

Prior-auth scrubber For billing leads
● Studio · template walk-through

Turns the signed audit chain into the exact spreadsheet your auditor expects — ready before the request lands.

Audit-evidence exporter For compliance officers

Each is a Studio template. Bring your use case — we'll build it with you on evaluation data, no BAA required to try.

Get started

Bring governed AI
into your organization.

Start with chat, workflows, internal tools, APIs, or agents. HASP gives every path the same compliance, policy, and audit foundation.