Compliance infrastructure for clinical AI agents

Prove what your AI agent did to patient data.

A tamper-evident, auditor-verifiable record of every action your clinical AI takes — with policy enforced before it acts. Drop-in. No raw PHI stored.

clinproof · prior-auth agent · sealed audit log
ALLOW  read_meds        12 recs   policy: ok
ALLOW  submit_prior_auth 3 recs   policy: ok
DENY   read substance-use         → 42 CFR Part 2 blocked
DENY   bulk-pull 5,000 records    → minimum-necessary breach

verify chain ………………………………  ✓ intact
tamper test  (edit record #1)  ✗ detected at #1
Built around the rules that matter
HIPAA audit controls42 CFR Part 2 OCR auditsJoint CommissionSOC 2-ready

A bouncer and a flight recorder

Three things, one drop-in SDK — no blockchain, no new infrastructure to run.

01 · ENFORCE

Policy before the action

Every agent action is checked first — blocked if it touches out-of-scope data or breaks minimum-necessary.

02 · SEAL

Tamper-evident record

Each action is sealed into an append-only chain. Any edit, deletion, or reorder is detectable — even by you.

03 · PROVE

Audit-ready, verifiable

Produce the evidence procurement and OCR want — and let an auditor verify it without trusting us.

Why not just build it yourself?

Because in compliance, who attests matters. An auditor trusts an independent, verifiable record over a vendor's own internal logs — and you can't self-build independence.

We store data-class labels, hashes, and opaque patient refs — never your raw PHI — so your patient data never leaves your system, and your BAA surface stays small.

Talk to us

If your agents touch PHI and you need to prove what they did, we'd like to hear how you handle it today. Working with a small number of design partners now.

deepak@clinproof.ai

Early access — building with design partners.