AI governance for hospitals · Built in Western Australia
Let clinicians use AI. Keep patient data in the hospital.
Tavrik sits inside your network. It replaces patient details before any AI tool sees them,
enforces your policy on every request, and writes the evidence into the audit systems you
already run. With a local model, nothing leaves the building at all.
No inbound path from the internet. Outbound connections only.
Providers out
LocalliveOllama, vLLM. Nothing leaves.
Anthropic, OpenAI, Azure, Bedrockliveplaceholders only, never patient data
37 clinical recognisers
in the healthcare pack: HL7 v2, FHIR, DICOM and Australian identifiers
2 clinical audit paths
HL7 v2 messages to your integration engine, and FHIR AuditEvent resources
3 deployment shapes
AU-region dedicated cloud, on-premises VM, and Kubernetes
0 lines of client code to change
the browser path needs nothing at all; the API path repoints a base URL and a key
The data path
A clinician pastes a handover note into ChatGPT. Before it leaves the hospital network,
Tavrik replaces the patient details with placeholders. The AI answers normally. On the way
back, the real details are restored. The provider never received them.
What the clinician typed
Mrs Eleanor Whitfield, MRN 4471902,
DOB 12/03/1948, presented with…
What the AI provider received
{NAME_1}, MRN {MRN_1},
DOB {DOB_1}, presented with…
What was recorded
request allowed · 3 items replaced
NAME, MRN, DOB · policy v3
delivered to Mirth and FHIR AuditEvent
The same policy applies whether the request came from the browser extension or from an
application through the API gateway. Prompts and answers are not stored. What is recorded is that a request happened, what kinds of details were found, and whether
it was allowed.
What a clinician's hospital sees
The console shows what is flowing through, what was replaced, where it was routed, and why it
was allowed or blocked. Every screen below is the live product, not a mockup.
Overview. Requests governed, patient details replaced, policy denials, connector health and spend. Traffic. Every request, what was replaced, which model handled it, and the decision trail behind each row. Audit. A tamper-evident chain, written in plain English, verifiable on demand. Costs. Spend over time, this month against last, and where it goes by provider and department.
Audit into your clinical systems
Evidence goes where your existing processes already look for it, rather than into another
console nobody opens.
Your integration engine
Audit events delivered as HL7 v2 messages over MLLP with TLS, to the integration engine you already run — Mirth Connect, Cloverleaf, Rhapsody and
Iguana are the common ones — and your integration team routes them like any other feed.
Your FHIR estate
FHIR R4 AuditEvent resources over HTTPS. Audit records only. Tavrik does not read or write clinical resources.
Your SIEM
Splunk HEC, Microsoft Sentinel and Microsoft Purview. The same categorical events, in the tools your security team already watches.
Dedicated single-tenant cloud in your region, an on-premises VM in your data centre, or your
Kubernetes cluster. Inside your network either way, with the option to route to a local model
so patient data never leaves at all.
Straight answers
Certification
We maintain control mappings for SOC 2, ISO 27001, HIPAA, the Australian Privacy Act
and the EU AI Act. We do not yet hold a SOC 2 or ISO attestation; a SOC 2 Type I is in
progress.
Customers
Tavrik is founder-led, and we are taking on our first hospital design partner. There
are no public reference customers yet.
Everything here
Every claim on this page is listed with its evidence in the repository, and the build
fails if a number appears without one. Ask and we will demonstrate it live.
Four weeks, one department, real clinicians. We install inside your network, enrol a pilot group on the browser extension, connect the
audit path to your integration engine or FHIR store, and hand you the evidence at the end.
You keep the audit log either way.