Most AI runs first and audits later. Vella OS puts one authority boundary in front of every action, keeps patient data behind a key the models never hold, and writes the evidence as it goes. This page explains how, in plain language, with the parts still in progress marked as such.
Every action Vella takes crosses a single Action Gateway. Nothing writes directly. The gateway checks policy, scores the risk of this action right now, applies the floors your practice cannot lower, and returns one of four verdicts.
A module declares what it may do (its actions, its tables, its tools) in a manifest. Access rules and row‑level security are generated from that declaration. A table nobody declared gets no policy; an action nobody registered is denied at runtime. The manifest is not documentation. It is source code.
If the risk engine is unavailable, verdicts escalate to a person. If the gateway is unavailable, writes stop. If the cache is unavailable, floors activate. Degraded mode produces more governance, not less.
Nothing the model emits may decide its own risk, approval or scope. The model proposes; code decides; a person approves when the verdict asks for one; verification proves what happened. Reasoning may be adaptive. Authority never is.
Most systems hide the button. Vella checks the permission — hiding a button never replaces a permission check.
Autonomy isn’t a switch for the whole practice. It is set per type of work, starts at Advise, and climbs only on verified results a named person has signed off. Some floors never move, whatever the track record.
A blended score is arithmetic nobody can audit. Vella keeps the facts separate so a reviewer can see exactly why.
Forces Advise for a practice, a type of work, a role or the whole platform, with a reason recorded. It forces advice, not off: switching Vella off would turn a safety control into an outage.
A practice earns the right to act when circumstances are safe — never the right to redefine unsafe circumstances as safe.
Before anything reaches a model, patient references are replaced with tokens. Only Azure Key Vault can turn a token back into a person, and only when a human needs to read it: an outreach message, a screen. Caches, events, logs and traces see tokens too.
Tokenization lowers the risk at the model boundary. It is not de‑identification: we hold the key, so tokenized data is still protected health information, inside a HIPAA environment, under a BAA. We won’t tell you otherwise.
Inference runs on Azure OpenAI inside Canopy’s private Azure boundary, in US regions, under Microsoft’s BAA. Practice data is never used to train models, and we require zero‑retention handling of prompts and responses.
Findings are surfaced by role rather than by patient name by default. Fields outside a user’s grant are simply absent from the response. Not blanked, not hidden behind a marker, absent.
If tokenization fails, the data does not enter the model. No exceptions.
Every action that crosses the gateway is written to an append‑only, hash‑chained audit trail with the verdict that allowed it. When an auditor asks to see your access controls, the answer is a query.
Every governed write produces an append‑only audit record: who or what acted, the verdict and why, the parameters, a correlation id and the time. Written by the gateway, never by the module. Retained seven years.
Every serious detection produces a sealed evidence package built on a patent‑pending forward‑secure hash chain: explainable to a CPA, exportable for forensics, with every access to the package logged.
Reviews, approvals, access and AI decisions are queryable because the architecture writes them as it runs, not assembled afterwards from screenshots and memory.
Chain of custody intact for HIPAA audits, investigations and disputes — and for the Tuesday someone simply asks why.
How Fraud Guard builds a case →Practices share nothing by accident. Isolation is enforced in the database itself, generated from the same manifests that define what each module may do. And what each role may ask Vella to do is a rule you can read.
Multi‑factor authentication is required for all access to systems holding PHI. Services authenticate with managed identities; databases accept identity‑based sign‑in only. Every action is attributable to a named person or a named service.
People and services get the minimum they need. Elevated access is granted just‑in‑time and expires. Access is reviewed quarterly, privileged roles monthly, and revoked within 24 hours of departure.
At most two sealed emergency accounts per tenant. Using one needs a declared incident, an authoriser and a witness; the credential is rotated immediately afterwards and every step is logged.
Employees and contractors have signed authorisation, background screening, HIPAA training and an NDA on file before access, and subcontractors sign their own BAA with us.
Cross‑tenant attempts are not silently refused — they are recorded as security events.
Encryption, keys, networks, incident handling and what happens to your data when you leave. None of it is novel. All of it is written down, enforced, and evidenced, or we say it isn’t yet.
Vella OS runs on Microsoft Azure in US regions. Databases, caches, key vaults and the message bus sit on private endpoints inside a virtual network; nothing holding PHI is reachable from the public internet. Infrastructure is defined as code and deployed through reviewed changes.
Secrets and the PHI token keys live in Azure Key Vault with soft delete and purge protection. Operations use keys in place (they are never exported) and every access to the vault is logged.
A documented plan with severity tiers and playbooks, including AI output leakage and prompt injection, and a dedicated HIPAA branch. A suspected PHI incident opens a bridge within fifteen minutes, engages the HIPAA Security Officer within the hour and outside counsel within four. You are notified within the HIPAA window, with the facts you need for your own notifications.
On request or at the end of the relationship, your data is returned in a documented, machine‑readable format within thirty days, or destroyed on your written instruction with destruction certified in writing. Audit records survive offboarding, because they are yours too.
If any part of the governance path is unavailable, verdicts escalate and writes wait for a person. Vella OS does not fail open. Backups are point‑in‑time and geo‑redundant, and restore tests sit in the go‑live gate rather than on a wish list, because a backup that has never been restored is a hope.
Documented, enforced, evidenced. If we cannot answer all three, the control is not real yet.
A security page should be the most honest page on a website. Here is what is in force, what is aligned, what is designed‑to, and what is still on the path.
In force. We sign a BAA with every practice, and our subcontractors sign one with us. PHI is PHI from the moment it arrives: in build, in testing, in production. There is no lighter standard for “just testing”.
Access control, audit controls, integrity and transmission security (45 CFR §164.312) are implemented as gateway, policy and audit behaviour, not as a policy document that asks people to remember.
Our control set is mapped to Annex A through a Statement of Applicability. Aligned, not certified, and we will say so until it is.
The AI governance model (earned autonomy, permanent floors, reconstructable verdicts, a human on every promotion) is designed to these frameworks.
On the path. We will share the timeline and the audit scope under NDA rather than a badge that isn’t earned yet.
HIPAA training before any PHI access and annually after, with records kept six years. There is no government “HIPAA certification”, so we describe completion as completion.
Ask us the hard questions. We would rather answer them now than after a signature.
Request the security packet →
Bring your compliance officer, your IT partner or your CPA. We will walk the architecture with them, share the security packet and the BAA, and mark what is live against what is still in progress.
The scalable operating system that actually improves financial performance on its own.