Security and HIPAAPre‑governed · not post‑audited

Trust is established before Vella acts. Not assumed after.

Most AI runs first and audits later. Vella OS puts one authority boundary in front of every action, keeps patient data behind a key the models never hold, and writes the evidence as it goes. This page explains how, in plain language, with the parts still in progress marked as such.

BAA with every practicePHI tokenized before any modelSeven‑year evidence chain
Vella proposesreasoning · adaptiveACTION GATEWAYthe authority boundaryPolicydefault: denyRisk and floorsscored, never self‑assertedPractice trust rulesearned per jobAuto executePropose and confirmRequire approvalBlockEvery governed write commits as one transaction: the change · the audit record · the event
On this page
The gateway

One boundary. Four verdicts.

Every action Vella takes crosses a single Action Gateway. Nothing writes directly. The gateway checks policy, scores the risk of this action right now, applies the floors your practice cannot lower, and returns one of four verdicts.

one transaction — the write never lands without its recordPolicyallow? default noRisk scorethis action, nowFloorsnever loweredVerdictone of fourWritethe changeAudit recordhash‑chainedEventpublished
Auto executeHigh confidence, low risk, inside permitted scope. It happens, and it is recorded.
Propose and confirmVella prepares it completely; a person confirms before anything moves. Expired proposals are never executed.
Require approvalElevated risk or scope. Escalated to the right person, who commits the change, the record and the event together.
BlockOutside permitted bounds. No action taken. The reason is written to the audit chain.
Manifest → policy

Policy is code

A module declares what it may do (its actions, its tables, its tools) in a manifest. Access rules and row‑level security are generated from that declaration. A table nobody declared gets no policy; an action nobody registered is denied at runtime. The manifest is not documentation. It is source code.

Degraded mode

Never fails open

If the risk engine is unavailable, verdicts escalate to a person. If the gateway is unavailable, writes stop. If the cache is unavailable, floors activate. Degraded mode produces more governance, not less.

Authority

The model never grants itself authority

Nothing the model emits may decide its own risk, approval or scope. The model proposes; code decides; a person approves when the verdict asks for one; verification proves what happened. Reasoning may be adaptive. Authority never is.

Most systems hide the button. Vella checks the permission — hiding a button never replaces a permission check.

Earned autonomy

Authority is hard to earn and easy to lose.

Autonomy isn’t a switch for the whole practice. It is set per type of work, starts at Advise, and climbs only on verified results a named person has signed off. Some floors never move, whatever the track record.

AdviseVella proposes.A person does the work.AssistVella prepares it fully.Runs once approved.ActVella does what it can.Informs, and escalates.Earned per practice × per type of work · promoted one step at a time · a bad run can drop twoEvidence is verified outcomes only — never the model’s own confidence
Every verdict is reconstructable

Six facts, not one number.

Case riskthis action, now
Evidence scoreverified outcomes
Authority tierbounded by policy
Floorpermanent · not lowered
Anomalynone flagged
Capwithin limit
VerdictPropose and confirm

A blended score is arithmetic nobody can audit. Vella keeps the facts separate so a reviewer can see exactly why.

Permanent floors
Post, void or reconcile a paymentAlways a named person.
Adjust a ledger or write anything offAlways a named person.
Sign a clinical recordOnly the clinician.
Change Vella’s own authorityNever. An agent may not alter its own authority.
The kill switch

Forces Advise for a practice, a type of work, a role or the whole platform, with a reason recorded. It forces advice, not off: switching Vella off would turn a safety control into an outage.

A practice earns the right to act when circumstances are safe — never the right to redefine unsafe circumstances as safe.

PHI and tokenization

Vella works on tokens. The key stays in the vault.

Before anything reaches a model, patient references are replaced with tokens. Only Azure Key Vault can turn a token back into a person, and only when a human needs to read it: an outreach message, a screen. Caches, events, logs and traces see tokens too.

THE RECORDencrypted at rest · private network · US regionsPatientMaria Alvarez · 04/12/1987ChartCrown #19 · seated 2:00 pmLedgerFee $1,240 · contracted $1,180TOKENIZED HEREthe boundary is structural, not a runtime settingto the modelto a person onlyWHAT THE MODEL SEESPatientphi:8c41…a7f2ChartCrown #19 · seated 2:00 pmLedgerFee $1,240 · contracted $1,180Key Vault · the only place a token can be reversedif the vault is unreachable, the action is blockedRedis · events · logs · tracessee tokens, not namesDetokenized only to renderto a human — e.g. a message
Honest about scope

It is still PHI. We treat it that way.

Tokenization lowers the risk at the model boundary. It is not de‑identification: we hold the key, so tokenized data is still protected health information, inside a HIPAA environment, under a BAA. We won’t tell you otherwise.

Where inference runs

Your patients never train a model.

Inference runs on Azure OpenAI inside Canopy’s private Azure boundary, in US regions, under Microsoft’s BAA. Practice data is never used to train models, and we require zero‑retention handling of prompts and responses.

What each person sees

Minimum necessary, by role.

Findings are surfaced by role rather than by patient name by default. Fields outside a user’s grant are simply absent from the response. Not blanked, not hidden behind a marker, absent.

If tokenization fails, the data does not enter the model. No exceptions.

The evidence chain

Seven years of every decision. A query, not a binder.

Every action that crosses the gateway is written to an append‑only, hash‑chained audit trail with the verdict that allowed it. When an auditor asks to see your access controls, the answer is a query.

Fri 2:14 amSentinel · finding openedRequire approval#8c41… ← #genesisFri 8:02 amD. Patel · approvedCommitted#a980… ← #8c41Fri 8:02 amrcm.claim.submitAuto execute#c6bf… ← #a980Fri 9:40 amVella · recall listPropose and confirm#e3fe… ← #c6bfMon 7:15 amAuditor · readLogged#1013d… ← #e3feAppend‑only · each record carries the hash of the one before it · seven‑year retention · PHI appears as tokens, never names
The record

Who, what, verdict, when.

Every governed write produces an append‑only audit record: who or what acted, the verdict and why, the parameters, a correlation id and the time. Written by the gateway, never by the module. Retained seven years.

Fraud Guard

Fraud Guard seals its findings.

Every serious detection produces a sealed evidence package built on a patent‑pending forward‑secure hash chain: explainable to a CPA, exportable for forensics, with every access to the package logged.

How audits go

Evidence as a by‑product.

Reviews, approvals, access and AI decisions are queryable because the architecture writes them as it runs, not assembled afterwards from screenshots and memory.

Chain of custody intact for HIPAA audits, investigations and disputes — and for the Tuesday someone simply asks why.

How Fraud Guard builds a case →
Access and tenancy

Every row knows its practice. Every action knows its person.

Practices share nothing by accident. Isolation is enforced in the database itself, generated from the same manifests that define what each module may do. And what each role may ask Vella to do is a rule you can read.

ROW‑LEVEL SECURITY · generated from the manifestNorthlakeclaim 88‑4127Willow Parkclaim 51‑0093Northlakepayment · $1,180Cedar Ridgerecall listNorthlakeappointment · Thu 2:00sessionNorthlakeA query without a practice context matches nothing. Fails closed.
PERSONA × ACTION · rules live as dataBookMessageClaimPaymentVoidFront deskBillingOffice managerOwnerIllustrative. Auto · propose · approval · block — changed by compliance, not engineering.
Identity

MFA, and no shared passwords.

Multi‑factor authentication is required for all access to systems holding PHI. Services authenticate with managed identities; databases accept identity‑based sign‑in only. Every action is attributable to a named person or a named service.

Privilege

Least privilege, elevated briefly.

People and services get the minimum they need. Elevated access is granted just‑in‑time and expires. Access is reviewed quarterly, privileged roles monthly, and revoked within 24 hours of departure.

Emergencies

Break‑glass, under dual control.

At most two sealed emergency accounts per tenant. Using one needs a declared incident, an authoriser and a witness; the credential is rotated immediately afterwards and every step is logged.

Workforce

Nobody touches PHI untrained.

Employees and contractors have signed authorisation, background screening, HIPAA training and an NDA on file before access, and subcontractors sign their own BAA with us.

Cross‑tenant attempts are not silently refused — they are recorded as security events.

Infrastructure, incidents and your data

The unglamorous parts, done properly.

Encryption, keys, networks, incident handling and what happens to your data when you leave. None of it is novel. All of it is written down, enforced, and evidenced, or we say it isn’t yet.

Infrastructure

Built on Azure, inside a private boundary.

Vella OS runs on Microsoft Azure in US regions. Databases, caches, key vaults and the message bus sit on private endpoints inside a virtual network; nothing holding PHI is reachable from the public internet. Infrastructure is defined as code and deployed through reviewed changes.

TLS 1.2+in transit, everywhere
Encrypted at restdatabase, storage, keys
Private endpointsno public path to PHI
Keys

Keys stay in the vault.

Secrets and the PHI token keys live in Azure Key Vault with soft delete and purge protection. Operations use keys in place (they are never exported) and every access to the vault is logged.

Managed identitiesper service, per secret
No connection stringsidentity‑based sign‑in only
Incident response

Suspicion is the threshold, not certainty.

A documented plan with severity tiers and playbooks, including AI output leakage and prompt injection, and a dedicated HIPAA branch. A suspected PHI incident opens a bridge within fifteen minutes, engages the HIPAA Security Officer within the hour and outside counsel within four. You are notified within the HIPAA window, with the facts you need for your own notifications.

15 minP1 bridge open
1 hourSecurity Officer engaged
60 daysCovered Entity notification, at most
Your data

It belongs to you. We are stewards.

On request or at the end of the relationship, your data is returned in a documented, machine‑readable format within thirty days, or destroyed on your written instruction with destruction certified in writing. Audit records survive offboarding, because they are yours too.

30 daysexport, machine‑readable
Certifieddestruction in writing
Never trained onyour patients, ever
Resilience

Degraded mode means more governance.

If any part of the governance path is unavailable, verdicts escalate and writes wait for a person. Vella OS does not fail open. Backups are point‑in‑time and geo‑redundant, and restore tests sit in the go‑live gate rather than on a wish list, because a backup that has never been restored is a hope.

Never fails openby design
Geo‑redundantbackups

Documented, enforced, evidenced. If we cannot answer all three, the control is not real yet.

Compliance programme

Where we are, plainly.

A security page should be the most honest page on a website. Here is what is in force, what is aligned, what is designed‑to, and what is still on the path.

HIPAA Business AssociateIn force

In force. We sign a BAA with every practice, and our subcontractors sign one with us. PHI is PHI from the moment it arrives: in build, in testing, in production. There is no lighter standard for “just testing”.

Technical safeguards in codeIn force

Access control, audit controls, integrity and transmission security (45 CFR §164.312) are implemented as gateway, policy and audit behaviour, not as a policy document that asks people to remember.

ISO 27001:2022 alignedAligned

Our control set is mapped to Annex A through a Statement of Applicability. Aligned, not certified, and we will say so until it is.

ISO/IEC 42001 and NIST AI RMFDesigned to

The AI governance model (earned autonomy, permanent floors, reconstructable verdicts, a human on every promotion) is designed to these frameworks.

SOC 2On the path

On the path. We will share the timeline and the audit scope under NDA rather than a badge that isn’t earned yet.

Training and workforceIn force

HIPAA training before any PHI access and annually after, with records kept six years. There is no government “HIPAA certification”, so we describe completion as completion.

What we won’t say
We will not call anything certifiedthat isn’t.
We will not call a chain tamper‑proofuntil the maths says so.
We will not call Vella autonomousfor work a person has not yet verified.
We will not let Vella touch a clinical record.A clinician signs those.

Ask us the hard questions. We would rather answer them now than after a signature.

Request the security packet →

Governance isn’t a layer you add. It’s the foundation everything runs on.

Bring your compliance officer, your IT partner or your CPA. We will walk the architecture with them, share the security packet and the BAA, and mark what is live against what is still in progress.

BAA on requestArchitecture walkthrough with our CTOSubprocessor list under NDA
© 2026 Canopy Dental Inc.PrivacyTermsHIPAA noticeVella™ · What‑If™ · Sentinel™ patent pending
Intelligent practice. Zero friction.