Your data never
meets our servers.
Martlet AI deploys inside your environment — on-premises, in your private cloud, or air-gapped. There is no vendor cloud in the data path, no external AI API call, and PHI never leaves your network. Your existing security controls stay in effect, because nothing ever leaves them.
- Zero
PHI leaves your network — by architecture, not policy
- 0
external AI API calls in the data path
- 3
deployment models: on-premises, private cloud, air-gapped
- 100%
of AI decisions recorded in the audit trail
One boundary. Everything inside it.
The entire pipeline — ingestion, models, validation, review, exports — runs inside your network boundary. The diagram is short because the data path is.
- 01EHR + claims feeds (FHIR R4, HL7, extracts)
- 02Document store (notes, PDFs, scans)
- 03Martlet AI engine — models, validation, audit log
- 04Reviewer UI + exception queues
- 05Exports: submission deltas, packets, reports
On-premises
Runs on your hardware, inside your data center, under your physical controls.
Private cloud (VPC)
Your AWS, Azure, or GCP tenancy — your IAM, your SIEM, your network rules.
Air-gapped
Fully disconnected environments. Versioned release packages, applied by your team on your schedule.
SOC 2 attests to how a vendor handles your data.
In our deployment, the vendor doesn’t handle your data.
Security & compliance
The controls in effect are yours
- HIPAA-aligned by deployment model — PHI stays under your existing safeguards, and we sign a BAA
- Our policies and controls map to the requirements of HITRUST CSF, NIST 800-53, SOC 2, and ISO 27001
- Your SIEM, IAM, network segmentation, and monitoring apply unchanged — we run inside them
- Records and audit trails retained to your policy — CMS can audit ten years back; the trail is built for it
AI governance
Governed AI, not a black box
- Pacific AI certified for healthcare AI governance
- Every model versioned; every release tested before it touches production charts; every rollback one step
- Deterministic outputs — the same chart under the same configuration produces the same result, every time
- Every AI decision recorded: who acted, what changed, when, with which model version
Your data
Yours, and only yours
- No PHI leaves your network, and no subprocessors sit in the data path — there is no one downstream to vet
- Your data trains nothing outside your environment
- Underlying models are built on public clinical text and proprietary annotated datasets developed by John Snow Labs
- Licensed as software: no per-token fees, no per-chart fees, no success commission
What security reviewers ask us.
Is Martlet AI HIPAA compliant?
Martlet AI is HIPAA-aligned by deployment model: the platform runs inside your environment, so PHI remains under your existing HIPAA safeguards at all times, and we execute a Business Associate Agreement. Because no PHI flows to Martlet AI's systems, the strongest control is architectural — there is no vendor data path to secure.
Are you SOC 2 or HITRUST certified?
Our policies and controls map to the requirements of SOC 2, HITRUST CSF, NIST 800-53, and ISO 27001. But the more important answer is architectural: those certifications attest to how a vendor protects customer data in the vendor's environment — and in our deployment model, your data never enters our environment. The controls in effect are the ones your security team already runs.
Where does PHI go?
Nowhere. Charts, claims, and every model inference stay inside your network — on-premises, in your private cloud tenancy, or air-gapped. There are no external AI API calls in the data path and no subprocessors touching PHI.
Do you train models on our data?
Your data trains nothing outside your environment. The underlying medical language models are built on public clinical text and proprietary annotated datasets developed by John Snow Labs. Feedback from your reviewers tunes behavior inside your deployment — it never leaves your network.
How do model updates work in an air-gapped deployment?
Through versioned, controlled release packages that your team applies on your schedule. Every release is tested before it ships, every model is versioned, and rollback is one step — so an air-gapped environment stays current without ever opening a connection.
What does the audit trail capture?
Every AI decision and every human action: who acted, what changed, when, and with which model version — across coding, review, and export. Outputs are deterministic under a fixed configuration, so any past result can be reproduced and defended, including three years later under RADV.