For developers & platform teams

Build HIPAA-compliant AI
on a platform built for regulated work.

Use HASP as the HIPAA-compliant foundation for your AI products, agents, and workflows. Identity, policy, audit, compliance, and PHI handling — handled at the gateway, so you can focus on your product.

Compliance · frameworks we ship under
Independently validated HIPAA BAA on every paid plan
Report under NDA SOC 2 Type II · attested
Certification in progress HITRUST CSF e1
EU + UK GDPR Art. 17 · 20 · 30
Active CCPA / CPRA California
Active + CPPA-ready PIPEDA Canada
Developer surfaces

Two entry points. One governed substrate.

Whether you're integrating AI into an existing product or building autonomous agents, every call inherits identity, policy, audit, and PHI handling.

01

Public API

Embed HIPAA-compliant AI into your existing products and systems. PHI policy enforcement (send under BAA, redact, or block) and a full audit trail at the gateway.

API docs →
02

Agent SDK

Build agents that can act under scoped, revocable authority. Every tool invocation authorized, identity-scoped, and recorded.

SDK reference →
03

Agent Identity & Delegated Authorization

Agents as first-class identities. OAuth 2.1 + Rich Authorization Requests for scoped, auditable, revocable agent permissions. Includes the standards-aligned A2A protocol.

A2A protocol →
04

PHI Handling

PHI detection, redaction, and de-identification at the gateway. Configurable per-org. No PHI leaves your governed perimeter without policy approval.

Trust center →
Policy enforcement

Rules before action. Not after the fact.

Every API call and agent tool invocation passes through the policy engine before execution. Define rules per-org, per-surface, per-agent. Denials are logged with full context.

● Gateway evaluation order
  1. Authenticate caller (User / ApiKey / Agent)
  2. Resolve org context and permissions
  3. Evaluate policy rules
  4. Scan for PHI — allow under your BAA, redact, or block, per org policy
  5. Route to inference provider
  6. Sign response to audit chain
Signed audit events

Every action recorded. Every record verifiable.

Hash-chained, Ed25519 signed, RFC 3161 anchored. Customers download the chain as plain JSON and verify it independently — no HASP software required.

Audit architecture →
Built in

What every call inherits.

None of this is something you configure per call. Whether a request comes through the API, the Agent SDK, or any other surface, the platform enforces the same guarantees automatically.

Identity — first-class user, API key, and agent identities
Policy enforcement — rules evaluated before any action
Audit integrity — hash-chained, Ed25519 signed, RFC 3161 anchored
Compliance posture — HIPAA, SOC 2, HITRUST, GDPR, CCPA, PIPEDA
PHI handling — detection, redaction, de-identification

Start building

Governed AI,
ready on day one.

Request API access, explore the SDK, or book a technical walkthrough. Every surface inherits identity, policy, audit, and PHI handling at the gateway.