Security and data handling
Updated October 2, 2026
Status: Practice demos are open. ILAI is in daily use by its founder and first patients, and we’re preparing our first practice deployments.
Where ILAI runs
- Its own server per practice. We deploy each practice on its own server with its own database. Practices don't share one.
- A private network. In practice deployments today, ILAI is reached over an encrypted private network (Tailscale), not the open internet. We set up secure private access on each clinician's and patient's phone or computer during setup.
- Encrypted. Traffic is encrypted in transit (HTTPS), and the server's disks are encrypted at rest.
ILAI for iPhone, for individuals, is coming to the App Store. It will run on separate infrastructure from practice deployments, with its own privacy terms, published before launch. This page describes practice deployments.
Who can see what
- Each clinician and patient has their own login. Passwords are stored as salted hashes, and sessions use a secure, HTTP-only cookie.
- Every change to a patient's record is written to an append-only log: what changed, and when.
- Proactive messages go only to the patient, inside ILAI.
Services that process patient data
Patients log meals and exchange messages inside ILAI. Records are stored in the practice's ILAI environment; the services below describe where data is processed.
- Oracle Cloud Infrastructure hosts each practice's dedicated ILAI environment: the server, its encrypted disk and the database.
- Tailscale provides the private network through which the practice and its patients reach that environment; no public port is open.
- Anthropic (Claude) writes ILAI's explanations and answers from the record it is given. Patient data is not used to train a model.
- Apple Health, on the patient's own iPhone, is where wearable data comes from. The patient chooses what to share.
- Email, sent through Resend, carries account invitations, a generic alert when a message is waiting ("You have a new message in ILAI. Sign in to read it."), and the practice's weekly report. Invitation and message-alert emails contain no clinical content. The weekly report is emailed to the practice's chosen address and contains patient findings.
How ILAI makes answers reviewable
- Rules and calculations come first. The requisition, dose changes, statistics and verdicts are computed from the record. The model is handed those figures and told to quote them, not recompute them.
- Lab answers show the results they used, so a clinician can check them.
- Configured rules flag recorded critical values, such as a systolic blood pressure of 180 or higher, for review. These checks depend on the data available and do not provide emergency monitoring; urgent findings follow your practice's own process.
Approvals
ILAI proposes dose and protocol changes, with the calculation behind each one. ILAI prepares proposed changes for review; nothing is applied until an authorized practice account records acceptance, with who and when. Patient accounts cannot accept dose or protocol changes. Which accounts are authorized is the practice's own setting; ILAI checks the account role, and prescribing responsibility remains with the treating clinician. Checkpoint rules flag a result; they don't change a dose on their own. A signed clinician review record, with dual-review badges and document upload, is in development.
HIPAA
Practice environments use encrypted storage and connections, private-network access and a record of changes. We don't describe ILAI as HIPAA compliant until the pieces below are in place for your practice.
Underway before launch
- Business associate agreements with each vendor that handles patient data.
- A documented risk assessment, and an independent security review.
- The signed clinician review record.
- A wider review of access controls for each role in a practice.
Questions
Security and procurement questions go to [email protected]. We can walk through current controls, deployment plans and outstanding requirements for your practice. For how this website handles your information, see the privacy policy.