A deterministic six-condition gate authorizes every dollar, a hash-chained WORM ledger records it, and an unconfigured integration returns a typed refusal — never a simulated success.
Trust here is not a badge wall. The register below separates what is verified in the current build from what is gated on a named human or legal step.
Verified-green = tested in the current build. Gated = awaiting a named gate. Never blurred.
{
"code": "DISPOSED",
"passed": false,
"status": "HALTED",
"firstFailed": "provider_screening"
}The architecture is the security story.
Every posting lands in a write-once, hash-chained double-entry ledger — integer cents, cryptographic signature chaining, fork/orphan/cycle detection — so the audit trail is assembled as events happen, not reconstructed after.
Deploy across multi-tenant GCP, single-tenant dedicated VPC with Customer-Managed Keys (CMEK), or fully air-gapped on-premise Kubernetes with local Dex IdP SSO and edge model inference.
Authentication is enforced at the edge for every request with step-up re-auth, and live OIG-LEIE/NPPES provider sanction screening is evaluated as a core condition of the settlement gate.
Above the settlement gate sit independent halt controls: when something is wrong the system stops, it does not reconcile later.
As a registered HIPAA clearinghouse shteg.ai is a covered entity; where a BAA is not yet in place, the integration fails closed.
Five controls are tested code in the current build; five certifications wait on named audits, opinions, and programs. No certification below is presented as final — when a gate clears, the register moves.
Run the identical 6-Condition Conjunction Gate, Zero-PHI DLP engine, and SHA-256 Merkle WORM Ledger — anywhere your compliance protocol requires.
Comparing controls across Enterprise Cloud, Dedicated VPC, and Air-Gapped Sovereign tiers.
| Feature / Control | Enterprise Cloud | Enterprise Dedicated VPC | Sovereign On-Prem / Edge |
|---|---|---|---|
| Hosting | Multi-tenant managed cluster, instant provisioning | Single-tenanted isolated GCP VPC managed by Shteg.ai | Air-gapped / local Kubernetes (Helm chart in development) or K3s edge appliance |
| Infrastructure | Fully managed Cloud Run + Cloud SQL + Cloud Healthcare FHIR R4 | Dedicated VPC, Private Service Connect, Dedicated Cloud SQL & FHIR Store | On-prem Postgres + S3/GCS-compatible object storage + Local AI |
| Identity & SSO | Auth0, GCP Identity Platform, Google Workspace, Microsoft Entra ID | Okta, Entra ID, Auth0, PingIdentity, SAML 2.0 / OIDC via Dex | Custom LDAP, Active Directory, Local Identity Provider via Dex |
| Key Control & Encryption | GCP KMS envelope encryption (AES-256 at rest & TLS 1.3 in transit) | Customer-Managed Encryption Keys (CMEK via GCP KMS / Cloud HSM) | Bring-Your-Own-Key (BYOK); on-premise HSM integration (PKCS#11, HashiCorp Vault) on the roadmap |
| WORM Ledger & Audit | Append-only, trigger-protected SHA-256 hash-chained audit ledger; Cloud Storage WORM anchoring in rollout | Dedicated immutable WORM bucket with customer KMS key signing | Local append-only WORM disk array with hardware cryptographic anchor |
| AI & LLM Processing | Managed GCP Vertex AI (Gemini 2.5 Pro / Flash); prompts are not used to train models | Dedicated Private Vertex AI Endpoints or reserved capacity | On-prem local LLM inference (Ollama / vLLM / OpenLLM edge nodes) |
| Data Residency | US Multi-region (GCP us-east1 / us-east4) | Any customer-selected GCP region or sovereign cloud zone | On-premise local data center / local NVMe storage (100% local control) |
| Compliance & Assurance | HIPAA BAA, DPA, 6-Condition Conjunction Gate; SOC 2 audit planned (not yet certified) | CMEK, custom HIPAA BAA, DPA, 6-Gate Conjunction; SOC 2 audit planned (not yet certified) | Customer-owned compliance envelope + Shteg hardening verification scripts |
| Support & SLA | Priority support; uptime commitments set per contract (no published SLA yet) | Dedicated technical contact; uptime and response commitments set per contract | L3 engineering support + deployment & upgrade assistance, per contract |
No real dollar has moved. No real PHI has flowed.
What is real: the architecture — hash-chained ledger, settlement gate, and reconciliation waterfall, tested in the current build — the Type-2 organizational NPI and registered HIPAA clearinghouse identity, and the doctrine. We register capability as capability, never as traction.