Healthcare
AI over clinical and organisational documents, inside the provider's network
Protocols, guidelines, internal procedures and clinical documentation searchable in plain language, on the provider's own infrastructure — with no transfer to an external vendor.
Health data is a special category under Article 9 GDPR: the required level of protection is higher, and every transfer has to be justified and documented. Keeping processing inside the organisation is the simplest way not to open that chapter at all.
The first use case is not the clinical one
The immediate value of a system like this in a healthcare organisation is not diagnostic support: it is organisational documentation, which is vast, changes constantly, and has to be consulted under pressure.
Operating protocols, ward procedures, adopted guidelines, medicine information notes, supply contracts, safety procedures. Material that exists, is formally in force, and cannot be found at the moment it is needed.
Answering “what is the current procedure in this case” by citing the document in force, and not the one superseded two revisions ago, is a document-management problem before it is an AI problem. It is also where retrieval with cited sources gives the sharpest result.
Why a closed perimeter simplifies the assessments
- No transfer to an external vendor means no processor to appoint for this purpose and no chain of sub-processors to map.
- After the first run the engine works without a network: it can sit on isolated segments, where an external service would not be reachable anyway.
- Roles, and the filter applied before generation, prevent an answer being built on documents the person asking could not open.
- The daily backup holds the application database and an index snapshot together, so a restore returns the system to a consistent state rather than two mismatched halves.
The software reduces the number of questions to assess; it does not remove them. Impact assessment, legal basis, security measures and minimisation remain the organisation's responsibility. We work through those with you during analysis, rather than selling certifications we do not hold.
Realistic applications
- Consulting protocols and procedures with a citation to the revision currently in force.
- Searching adopted guidelines and literature, in Italian and English.
- Technical documentation for equipment and devices, often long and available only in English.
- Administrative and procurement documentation: specifications, maintenance contracts, supply terms.
- Training and onboarding, with one place to check the current procedure.
Frequently asked questions
- Can it be used on health data?
- Technically yes, and keeping processing on the organisation's own infrastructure removes the question of transfer to a third party. Legally, health data remains a special category under Article 9 GDPR: a legal basis, an impact assessment and appropriate measures are still required, which the software supports but does not replace.
- Can it run on an isolated network?
- Yes. The first run downloads and verifies the components; from then on the engine needs no connectivity. That is the intended arrangement for network segments separated from the outside.
- Can it be used to support clinical decisions?
- That is not what we propose it for. It returns passages with their provenance from documentation you supplied: it is a document-consultation tool. Any use in support of clinical decisions would fall under a different regulatory framework and must be assessed separately, beforehand rather than afterwards.
- How is the archive kept current when procedures change?
- Reindexing an updated document takes minutes, not a retraining run. The critical point is organisational rather than technical: if superseded revisions stay in the archive, the system can cite them. Version governance remains the precondition for answers being reliable.
Ready to run RAG on your own infrastructure?
Start with the open-source Community edition, or talk to us about Pro with structured extraction, SSO, audit log and SLA.