Validated with partners in Aalborg
Aalborg, Denmark

Healthcare AI

EveryAIrequestinyourorganisation:
controlled,logged,andproven.

CareProxy is the control plane for AI in healthcare. We stop patient data before it leaves the building, prove what your AI did, and can stop an agent that goes wrong. Cloud or local: you choose the model, we deliver the control and the proof.

Designed to support compliance with

GDPR EU AI Act NIS2 ISO 27001

Validation partners · Danish enterprise

Treat Systems Judex

What is CareProxy?

A security layer that lets healthcare staff use AI without patient data ever leaving the hospital.

No new workflow for the clinician. No patient data in the cloud. CareProxy sits invisibly in the network and looks after it all.

Become compliant now

Meet GDPR, the EU AI Act and NIS2 today, instead of banning AI and waiting for legislation.

Keep the best AI

Your staff keep using ChatGPT and other top models. CareProxy simply sanitises the request first.

Prove it to the regulator

Every single AI request is logged with cryptographic proof. Export the documentation with one click.

Regulatory reality

The rules already apply. The rest is on the way.

Regulation (EU) 2024/1689, as amended by the Digital Omnibus (final Council adoption 29 June 2026)

The EU's Digital Omnibus (adopted 29 June 2026) moved the AI Act's high-risk deadlines, but it did not stop the clock: GDPR, NIS2 and DORA apply today, transparency obligations land in weeks, and the high-risk regime arrives in December 2027 with registration and an advantage for early movers.

  • In force now
    GDPR · NIS2 · DORA
    Fines of up to 4% of global turnover, and incident reporting is live. Shadow AI is a GDPR risk today, not in 2027.
  • 2 Aug 2026
    AI Act Article 50: transparency
    Users must be informed when interacting with AI, and AI-generated content must be labeled. Not deferred.
  • 2 Dec 2026
    Watermarking for existing systems
    Labeling obligations reach systems already on the market, and new prohibitions take effect.
  • 2 Dec 2027
    The high-risk regime (Annex III)
    Risk classification, audit logging, output monitoring and fail-safe, with a registration mechanism and grandfathering.
  • 2 Aug 2028
    High-risk in regulated products
    Including AI embedded in medical devices (Annex I).

What the high-risk regime requires

Four obligations that apply from December 2027. Several of them are effectively required by GDPR and NIS2 already.

  • 01 Risk classification of all AI systems processing patient data
  • 02 Legal-grade audit log per AI request, available to the regulator on demand
  • 03 Technical documentation and ongoing monitoring of AI outputs
  • 04 Fail-safe mechanisms: AI must be interruptible at any time
Grandfathering rewards early deployment

Systems in operation before the deadlines avoid the full high-risk obligations until substantially modified. The cheapest path to compliance is the one you deploy now.

57%
Shadow AI in healthcare
Wolters Kluwer Health, 2025
DKK 65M
Avg. cost of a data breach
IBM Cost of Data Breach, 2024

How it works

Follow one request through CareProxy.

From sensitive prompt to safe answer in milliseconds.

How it works

Follow one request through CareProxy.

From sensitive prompt to safe answer in milliseconds.

  1. 01
    Prompt & redactionA clinician's prompt is written with personal data; CareProxy masks the CPR and name in under 1 ms.
  2. 02
    Safe routingClean requests go to Cloud AI; confidential data routes to Local AI and never leaves the building.
  3. 03
    Agent stoppedAn AI agent tries to exfiltrate records. CareProxy blocks it instantly.
  4. 04
    Everything loggedEvery AI action is written to a hash-chained, court-ready audit log in real time.

For the CISO

Compliance you can prove, in real time.

Track every AI request live. See what was blocked, what went to cloud, and prove it all with one click when the regulator calls.

  • Live overview of all AI traffic
  • 100% of calls logged and auditable
  • One-click forensic export for regulators
CISO Dashboard Live

Requests today

14,205

Blocked locally

13%

To cloud

87%

● Low-risk → Cloud AI ● High-risk → Local AI
chain_integrity: OK · 14,205 entries verified
audit-log · hash-chained
Decision
Payload hash (SHA-256)
Integrity
DLP_BLOCK
sha256:9c1f…a042
OK
ROUTE_CLEAN
sha256:b73a…8e11
OK
INJECTION_BLOCK
sha256:4f2d…c7a9
OK
SHIELD_BLOCK
sha256:e08a…1f6b
OK
ROUTE_CLEAN
sha256:a142…9d3e
OK

Ed25519-signed · immutable · one-click forensic export

Proof of evidence

Cryptographic proof, ready for the regulator.

Every decision is hash-chained and signed. The log can't be altered without breaking the chain. When the regulator comes, you have indisputable evidence, not a CSV file.

  • Hash-chained, Ed25519-signed audit log
  • Verifiable without contacting CareProxy
  • Covers GDPR Art. 32, ISO 27001, NIS2

Try it yourself

Type a request. Watch the decision.

The same zero-trust layer we validated with partners, live in your browser. Type or pick a prompt and watch CareProxy classify and route it in under a millisecond. Nothing leaves your browser.

Try it yourself

Detected signals

  • PIIICD-10 diagnosis code
Triage
0.7 ms
Local AI

Patient data → your on-premise model. Never leaves the building.

Why CareProxy

The only one that does all four.

Healthcare detection
EU sovereignty
Compliance audit
No local AI required
Hyperscaler cloud AI Microsoft, Google
Enterprise AI security e.g. CrowdStrike, Trend Micro
Local open-source AI self-hosted LLM
CareProxy

Healthcare detection: Danish CPR (mod-11), clinical lexicon, contextual re-identification. EU sovereignty: patient data never leaves the hospital's own network (not merely 'EU data residency' in a vendor cloud). Compliance audit: cryptographic hash-chained GDPR/EU AI Act evidence. No local AI required: Shield runs without your own GPU or model operation.

Ready to take control of your AI infrastructure?

CareProxy is under active development. Join the waitlist to be notified as soon as pilot installations open.

Or reach out directly kontakt@careproxy.dk

Join the waitlist

Be among the first hospitals to get access to CareProxy's zero-trust AI routing. We'll reach out as soon as pilot installations open.