AI analytics that survive the security review.

A delivery methodology in development for health plans and value-based care organizations. Working AI analytics on the plan's own data, inside the plan's own environment, behind gates that fail closed. Built in the open. Looking for people who can break it.

health plans · value-based care · in development

The problem

Security reviews approve use cases: named data, a named build, a named outcome. They are good at that shape, and right to demand it.

AI enablement is not a use case. It is a way of working. Analytics changes daily and a use-case spec cannot. So every new application of AI becomes its own review, and capability stalls in the queue.

Meanwhile the work routes around the controls. Analysts reach for shadow AI without knowing they are out of compliance. The risk arrives anyway, unrecorded. And the numbers that do come back are confidently wrong, because metric definitions live in report code and analyst memory.

The concept

Change what security approves. Instead of every use case, forever, the security team approves a governed environment once. Then the daily questions run inside it, with no new review per question. A bounded, provable thing is something security knows how to say yes to.

What a gated output looks like

source: synthetic test harness, not client data
run_manifest: 2026-08-03T09:14:02Z analyst=a2 path=compose
metric_gate: PPPM trend 4.7% vs canonical 4.7% tolerance 0.1pp PASS
redaction: 0 identifiers in output PASS

Monospace on this site means verified. Numbers that are estimates are labeled as estimates.

Status

This is a methodology being built, not an operating company. Plain accounting of where it stands:

methodology: written. six gated stages plus a care plan
gate code: built. redaction + metric gates, fail closed, tested against golden files
identity kit: built. two-analyst test, synthetic harness only
clients: none yet, by design at this stage
current work: critique. plan operators, actuaries, security owners

If you run a plan, review its security, or sign off on its numbers, the most useful thing you can do is tell me where this breaks.