Every health system deploying AI needs assurance that clinical data is protected, AI decisions are traceable, and governance is native — not bolted on.
Request a Governance & Compliance BriefingBulletTrain is designed so that patient data never leaves the premises. The local clinical large language model, Bevan, runs entirely within your infrastructure. External AI models — from providers such as Anthropic and OpenAI — receive only non-sensitive orchestration queries. Each country runs its own sovereign BulletTrain instance with full data isolation.
Bevan LLM processes all patient-data queries on-premises. Clinical records, diagnostic data, and patient identifiers never leave your data boundary.
Orchestration queries, terminology lookups, and general reasoning tasks may cascade to external models. These requests are stripped of patient-identifying information before leaving the boundary.
BulletTrain isolates model inference from clinical data stores. The model router classifies every inbound request. Patient-data queries stay local with Bevan. Non-patient-data queries cascade to external models. No clinical data reaches an external endpoint.
Every inbound request is classified by the model router. The classifier determines whether the query contains or references patient data, clinical identifiers, or protected health information.
Patient-data requests are routed exclusively to Bevan LLM running on local infrastructure. The routing decision is logged to the append-only audit trail before execution.
Non-patient requests eligible for external models pass through a secondary validation layer that strips residual identifiers, confirms classification, and logs the delegation assertion before the request leaves the boundary.
BulletTrain maintains a complete, immutable record of every clinical AI interaction. From request classification through model inference to response delivery, every step is captured with cryptographic integrity.
Every audit entry is cryptographically linked to the previous entry. Tampering with any record invalidates the entire chain, making silent modification impossible.
When one agent delegates a task to another — or when a request cascades to an external model — the delegation is captured as a signed, verifiable assertion in the audit trail.
Audit records can only be appended, never modified or deleted. This ensures that the historical record of every clinical AI decision remains intact for regulatory review.
Every request carries a trace context across all microservices. End-to-end latency, routing decisions, and failure modes are visible through standard OpenTelemetry-compatible observability tools.
This is the most important safety feature in BulletTrain. When a clinician invokes an emergency action, that invocation is never blocked — not by policy configuration, not by billing status, not by jurisdiction rules, not by rate limits, not by any governance layer in the system.
In clinical emergencies, any delay caused by a governance check, an expired licence, or a misconfigured policy could cost a life. BulletTrain treats emergency break-glass as an absolute constraint that supersedes all other system rules.
Emergency invocations bypass all policy gates but are fully logged. The break-glass event is recorded with the clinician's identity, the invocation context, and a full audit trail. Governance review happens after the emergency — never during it.
BulletTrain's governance architecture is designed to align with the following regulatory frameworks and standards. Where noted, alignment reflects architectural design intent — not formal certification.
| Standard / Framework | Scope | Status |
|---|---|---|
| General Data Protection Regulation (GDPR) | Data residency, consent management, right to erasure | Architecture aligned |
| Health Insurance Portability and Accountability Act (HIPAA) | Access controls, audit trails, encryption, minimum necessary | Architecture aligned |
| HITRUST Common Security Framework (HITRUST CSF) | Risk management, access control, incident response | Architecture aligned |
| ISO/IEC 27001 | Information security management systems | Architecture aligned |
| European Union Artificial Intelligence Act (EU AI Act) | High-risk AI transparency, human oversight, risk management | Architecture aligned |
| Audit Trail and Node Authentication (ATNA) | Secure node authentication, audit trail integrity | Architecture aligned |
| NIST Special Publication 800-207 | Zero Trust architecture principles | Architecture aligned |
This document outlines our governance architecture, standards alignment, and deployment model.
See the platform in action
Our team can walk through the governance architecture, data sovereignty model, and compliance alignment relevant to your organisation.
Request a Governance & Compliance Briefing