CLINICAL GOVERNANCE

Governance is not a feature.
It is the foundation.

Every health system deploying AI needs assurance that clinical data is protected, AI decisions are traceable, and governance is native — not bolted on.

Request a Governance & Compliance Briefing
DATA SOVEREIGNTY

How patient data stays within sovereignty boundaries.

BulletTrain is designed so that patient data never leaves the premises. The local clinical large language model, Bevan, runs entirely within your infrastructure. External AI models — from providers such as Anthropic and OpenAI — receive only non-sensitive orchestration queries. Each country runs its own sovereign BulletTrain instance with full data isolation.

Local clinical reasoning

Bevan LLM processes all patient-data queries on-premises. Clinical records, diagnostic data, and patient identifiers never leave your data boundary.

External models for non-clinical tasks

Orchestration queries, terminology lookups, and general reasoning tasks may cascade to external models. These requests are stripped of patient-identifying information before leaving the boundary.

SOVEREIGNTY BOUNDARY Clinical Data Patient records Bevan LLM Local inference Model Router Classifies requests External Models Non-patient queries only BOUNDARY Patient data — stays local Orchestration signals — may cross boundary
WORKLOAD ISOLATION

AI workload containment.

BulletTrain isolates model inference from clinical data stores. The model router classifies every inbound request. Patient-data queries stay local with Bevan. Non-patient-data queries cascade to external models. No clinical data reaches an external endpoint.

Three-layer detection pipeline

1

Request classification

Every inbound request is classified by the model router. The classifier determines whether the query contains or references patient data, clinical identifiers, or protected health information.

2

Data boundary enforcement

Patient-data requests are routed exclusively to Bevan LLM running on local infrastructure. The routing decision is logged to the append-only audit trail before execution.

3

External cascade validation

Non-patient requests eligible for external models pass through a secondary validation layer that strips residual identifiers, confirms classification, and logs the delegation assertion before the request leaves the boundary.

AUDIT TRACEABILITY

Every action traceable. Every decision auditable.

BulletTrain maintains a complete, immutable record of every clinical AI interaction. From request classification through model inference to response delivery, every step is captured with cryptographic integrity.

Hash-chained transparency ledger

Every audit entry is cryptographically linked to the previous entry. Tampering with any record invalidates the entire chain, making silent modification impossible.

Signed delegation assertions

When one agent delegates a task to another — or when a request cascades to an external model — the delegation is captured as a signed, verifiable assertion in the audit trail.

Append-only audit logs

Audit records can only be appended, never modified or deleted. This ensures that the historical record of every clinical AI decision remains intact for regulatory review.

OpenTelemetry distributed tracing

Every request carries a trace context across all microservices. End-to-end latency, routing decisions, and failure modes are visible through standard OpenTelemetry-compatible observability tools.

EMERGENCY SAFETY
Absolute Safety Constraint

Emergency invocations are never blocked.

This is the most important safety feature in BulletTrain. When a clinician invokes an emergency action, that invocation is never blocked — not by policy configuration, not by billing status, not by jurisdiction rules, not by rate limits, not by any governance layer in the system.

Why this matters

In clinical emergencies, any delay caused by a governance check, an expired licence, or a misconfigured policy could cost a life. BulletTrain treats emergency break-glass as an absolute constraint that supersedes all other system rules.

How it works

Emergency invocations bypass all policy gates but are fully logged. The break-glass event is recorded with the clinician's identity, the invocation context, and a full audit trail. Governance review happens after the emergency — never during it.

STANDARDS ALIGNMENT

Standards we design for.

BulletTrain's governance architecture is designed to align with the following regulatory frameworks and standards. Where noted, alignment reflects architectural design intent — not formal certification.

Standard / FrameworkScopeStatus
General Data Protection Regulation (GDPR)Data residency, consent management, right to erasureArchitecture aligned
Health Insurance Portability and Accountability Act (HIPAA)Access controls, audit trails, encryption, minimum necessaryArchitecture aligned
HITRUST Common Security Framework (HITRUST CSF)Risk management, access control, incident responseArchitecture aligned
ISO/IEC 27001Information security management systemsArchitecture aligned
European Union Artificial Intelligence Act (EU AI Act)High-risk AI transparency, human oversight, risk managementArchitecture aligned
Audit Trail and Node Authentication (ATNA)Secure node authentication, audit trail integrityArchitecture aligned
NIST Special Publication 800-207Zero Trust architecture principlesArchitecture aligned
RESOURCES

Download our Governance & Compliance Overview.

This document outlines our governance architecture, standards alignment, and deployment model.

We will use your details only to send the requested document. No spam.

See the platform in action

Cross-Border Orchestration Demo Agent Network Topology Demo

Ready to discuss governance for your deployment?

Our team can walk through the governance architecture, data sovereignty model, and compliance alignment relevant to your organisation.

Request a Governance & Compliance Briefing