A predictable engagement model designed for enterprise health systems, surgical centers (ASCs), and specialized clinical practices.
Whether deploying on our multi-tenant GCP healthcare cloud, a dedicated private VPC with CMEK, or on-premise sovereign Kubernetes, pricing is aligned directly with operational velocity.
Registered Type-2 NPI Clearinghouse · BAA-Covered · Direct EDI & Bank Rails
We partner directly with surgical practices and health systems to replace fragmented vendor stacks. Deploy clinical, clearinghouse, or treasury rails independently, or unify them across the complete loop.
Connect with our healthcare infrastructure team to model your practice's transaction volume, clearinghouse savings, and recovery contingency.
Three operational pillars designed to integrate modularly with existing infrastructure or operate as an end-to-end sovereign network.
ShtegMed EMR
ShtegRCM Network
ShtegPay Treasury
Run the identical 6-Condition Conjunction Gate, Zero-PHI DLP engine, and SHA-256 Merkle WORM Ledger — anywhere your compliance protocol requires.
Comparing controls across Enterprise Cloud, Dedicated VPC, and Air-Gapped Sovereign tiers.
| Feature / Control | Enterprise Cloud | Enterprise Dedicated VPC | Sovereign On-Prem / Edge |
|---|---|---|---|
| Hosting | Multi-tenant managed cluster, instant provisioning | Single-tenanted isolated GCP VPC managed by Shteg.ai | Air-gapped / local Kubernetes (Helm chart in development) or K3s edge appliance |
| Infrastructure | Fully managed Cloud Run + Cloud SQL + Cloud Healthcare FHIR R4 | Dedicated VPC, Private Service Connect, Dedicated Cloud SQL & FHIR Store | On-prem Postgres + S3/GCS-compatible object storage + Local AI |
| Identity & SSO | Auth0, GCP Identity Platform, Google Workspace, Microsoft Entra ID | Okta, Entra ID, Auth0, PingIdentity, SAML 2.0 / OIDC via Dex | Custom LDAP, Active Directory, Local Identity Provider via Dex |
| Key Control & Encryption | GCP KMS envelope encryption (AES-256 at rest & TLS 1.3 in transit) | Customer-Managed Encryption Keys (CMEK via GCP KMS / Cloud HSM) | Bring-Your-Own-Key (BYOK); on-premise HSM integration (PKCS#11, HashiCorp Vault) on the roadmap |
| WORM Ledger & Audit | Append-only, trigger-protected SHA-256 hash-chained audit ledger; Cloud Storage WORM anchoring in rollout | Dedicated immutable WORM bucket with customer KMS key signing | Local append-only WORM disk array with hardware cryptographic anchor |
| AI & LLM Processing | Managed GCP Vertex AI (Gemini 2.5 Pro / Flash); prompts are not used to train models | Dedicated Private Vertex AI Endpoints or reserved capacity | On-prem local LLM inference (Ollama / vLLM / OpenLLM edge nodes) |
| Data Residency | US Multi-region (GCP us-east1 / us-east4) | Any customer-selected GCP region or sovereign cloud zone | On-premise local data center / local NVMe storage (100% local control) |
| Compliance & Assurance | HIPAA BAA, DPA, 6-Condition Conjunction Gate; SOC 2 audit planned (not yet certified) | CMEK, custom HIPAA BAA, DPA, 6-Gate Conjunction; SOC 2 audit planned (not yet certified) | Customer-owned compliance envelope + Shteg hardening verification scripts |
| Support & SLA | Priority support; uptime commitments set per contract (no published SLA yet) | Dedicated technical contact; uptime and response commitments set per contract | L3 engineering support + deployment & upgrade assistance, per contract |
The honest register applies to money as much as to features: when a price is real, it will appear; until then, we sell the architecture and the conversation.
If the rail, the clearinghouse identity, and the doctrine fit your practice, the next step is a conversation — not a checkout.
No checkout, no quote generator. Tell us about your practice and where you lose margin today, and we will tell you honestly what is verified-green and what is still gated.