For healthcare organizations
Glyph Enterprise Regulated supports HIPAA-regulated workflows: potential PHI is evaluated on the device, and cloud destinations must be approved by your organization and backed by a BAA process before they can receive it.
Managed organization deployment and regulated workflows below describe planned capabilities. Account administration and policy authoring are implemented; client delivery, destination approvals, SIEM integration, and matter controls remain in development. Review current availability.
The operating reality
Clinical and administrative staff have the same AI pressure as everyone else, with none of the same latitude. The question is never whether the model is capable — it is whether anyone can say, afterward, where the patient information went.
Potential PHI
Glyph evaluates content for potential protected health information on the device. When Healthcare Data Mode is enabled under a qualifying contract, potential PHI can only be sent to destinations your organization has explicitly approved — provider, model, endpoint, and region recorded, with BAA status tracked per organization. Unknown cloud destinations are blocked by default.
Content is classified on the device. A suspected identifier is never sent to another AI service to be classified.
An approved destination records provider, model, endpoint, region, retention posture, BAA status, approver, and review date.
For regulated flows the full model response is inspected inside the trusted process before any of it is displayed or stored.
No-retention mode keeps conversation content in memory only, and disables the titles and summaries that would otherwise reconstruct it.
Keep the first workflow narrow enough to evaluate, but real enough to matter.
Enterprise Regulated and BAA eligibility are established first, with a compliance review. There is no self-serve path to Healthcare Data Mode.
Decide which models may receive potential PHI, and record the approval with its BAA status and review date.
A security administrator publishes a signed policy; enrolled devices enforce it and fail closed if it is missing or expired.
What good looks like
Local model workflows are available. Organization administration and policy authoring are implemented in the account control plane. Managed client rollout, destination approvals, SIEM delivery, and regulated workflows remain in development; see the Enterprise availability page.
Glyph supports HIPAA-regulated workflows; it is not "HIPAA certified," and detection is a layered heuristic rather than a guarantee. The interface reports "potential PHI" and describes tokenization as data minimization — not Safe Harbor de-identification.
Tell us about the workflow and the boundary around it, and we will help scope a practical first step.