AI security

Auditable AI. Provider review every time.

No model call without PHI redaction, governance metadata, and qualified provider review. Baseline, not a premium tier.

Responsible AI posture

Built for AI risk review.

01 — REDACTION

PHI redaction first

All 18 Safe Harbor identifiers scanned before any call. Unredactable PHI blocks it.

02 — REVIEW GATE

Provider review required

No AI output is final without qualified provider approval.

03 — AUDIT LOG

Immutable AI audit

Prompt hash, output hash, model ID, redaction status — append-only.

04 — PROVENANCE

Model + provider trace

Provider, model ID, request ID, classification — recorded per call.

05 — INJECTION DEFENSE

Prompt-injection block

Hard block on token-boundary, jailbreak, review-bypass patterns.

06 — RETENTION TAGS

Classification + retention

Tags map AI outputs to your data-handling policy.

Governance metadata

Every AI call leaves a paper trail.

Recorded per call

  • Provider identity and role
  • Model ID and version
  • Request ID for trace
  • PHI redaction status
  • Classification + retention tags

Available to reviewers

  • Append-only audit, org-scoped
  • Outbound JSONL or webhook
  • Per-org retention controls
  • Sign attestations + immutability

Enterprise-ready AI

Powered by IBM watsonx, built for ophthalmology.

ChartNav is engineered around enterprise-grade AI infrastructure that security and IT teams expect — and that ophthalmology practices can actually deploy.

IBM WATSONX

watsonx-aligned AI

Enterprise-grade AI infrastructure designed for healthcare workloads.

GOVERNANCE

watsonx.governance patterns

Provider, model, and request metadata recorded per call.

CLOUD READY

IBM Cloud architecture

AI, storage, and governance patterns aligned with IBM Cloud deployment.

FHIR R4

Standards-based exchange

FHIR R4 read-through for interoperability with existing EHR systems.

SBOM

Software bill of materials

SBOM published per release for procurement and vulnerability review.

ROADMAP

SSO & SCIM ready

Enterprise SSO (SAML / OIDC) and SCIM provisioning on the roadmap.