Runtime disclosure control for healthcare AI.

Three Gates sits in the data path between your workforce and the AI they use. On every request it detects sensitive data, tokenizes it before the model is invoked, withholds what policy disallows, and records the decision in an audit trail built for the questions your auditor, your carrier, and your board will ask.

A runtime control plane for AI in regulated organizations. Healthcare is our initial market; government and legal are on the roadmap.

Why identity controls are not enough

Epic controls who can open the chart. Three Gates controls what an AI acting for that user is allowed to receive.

Identity and access management answers whether a person may see a record. It does not answer what an AI working on that person’s behalf should be given to complete a task. A scheduling request does not need the diagnosis. A discharge summary does not need the Social Security number. A coding question does not need the patient’s name.

Access control is a decision about people. Disclosure control is a decision about content, made per request, at the moment the data is about to leave your boundary for a model. Three Gates makes that second decision, and records it, without replacing the identity stack you already have.

Access decides who may see the record. Disclosure decides what leaves with the request.

Before the incident

A BAA establishes the basis for the disclosure. It does not decide what is exposed when the vendor is breached.

Most healthcare AI programs rest on a business associate agreement with the model provider. That agreement matters: it is the contractual basis for sending PHI to the vendor at all. It is also, for most programs, the whole defense, right up until the day the vendor notifies you of an incident.

On that day the questions change. What did the vendor actually hold? Why did the model receive the full record for a task that needed three fields? Can you show, per request, what was disclosed and under which policy? A BAA does not help with those. A disclosure-control layer does, because it limited what left in the first place and recorded what did.

Three Gates does not change your notification obligations, and it does not make tokenized data “secured PHI” under the breach notification rule. What it changes is the risk assessment: a vendor that held typed placeholders with no rehydration key is a different incident from a vendor that held charts.

Permission is what the BAA gives you. Exposure is what you control.

Platform guardrails and Three Gates

Your cloud provider’s guardrails are a good start. Here is where they stop.

Bedrock Guardrails, Azure AI Language PII redaction, and Microsoft Purview each detect sensitive information in AI traffic and can block or mask it. If your organization runs one model on one platform for one purpose, that may be enough. Most healthcare organizations do not.

Tokenize, don't destroy

Platform guardrails

Mask or block. A masked value becomes a generic tag or a redaction mark, and nothing maps it back, so the workflow loses the value.

Three Gates

Detected values are replaced with typed tokens the model can reason over, and rehydrated on the return path, so the clinician gets a usable answer and the model never held the detected value.

Authorize the purpose and the tool, not just the text

Platform guardrails

Evaluate the text of a prompt or a response. None of them evaluates the request against a declared purpose, and none authorizes the tools an agent may call.

Three Gates

One policy evaluated per user, purpose, and destination across every provider you route to, with tool calls authorized against the purpose's scope.

Record the decision, not just the filter

Platform guardrails

Record the filter's assessment for the invocation, and in Purview's case the prompt and response themselves.

Three Gates

A record per supported invocation of what was detected, what was decided, what was transformed, where it went, and which policy decided it, with eligible FHIR workflows projected on demand as AuditEvent and Provenance.

Keep the platform guardrails on. Put the disclosure decision in front of them.

What Three Gates does

Data minimization, enforced at runtime.

Your AI policy says what may be disclosed to which system for which purpose. Three Gates is where that policy runs.

Every request, tool call, and model invocation passes through the same pipeline. Sensitive data is detected and classified. Detected values are replaced with typed tokens before the model is invoked, and rehydrated on the way back so the workflow still works. Policy decides what may happen to the request for this user, this purpose, and this destination, and withholds what it disallows. Tools are authorized against intent and scope. Human review is held in the path where policy requires it.

Each supported AI invocation records the detected data types, the authorization decision, the transformations applied, the destination and model, and the policy identifiers that decided it. Eligible FHIR workflows can be projected on demand as FHIR R4 AuditEvent and Provenance resources.

Detection is measured, not assumed. Read the local detection baseline.

One control plane and one set of policies across chat, the browser extension, agents, and integrated systems.

Built for regulated organizations

Vertical-agnostic architecture, configured for the proof each evaluator expects.

Three Gates is vertical-agnostic at the architecture level and configured per vertical for the policy and proof artifacts each evaluator expects.

Initial market

Healthcare

AI governance for hospitals, health systems, large practices, and digital health companies. PHI detection, purpose-bound authorization, tokenization before model invocation, BAA-covered routing, and an audit trail designed for HIPAA-derived analysis.

Roadmap

Government

CUI handling and 800-53-baseline-aligned controls for civilian and defense agencies handling sensitive-but-unclassified data.

Roadmap

Legal

Privileged communications and matter-scoped data isolation for firms running AI on client data.

Three ways to start.

Pick the door that matches where your organization is today.

Free

Take the AI readiness assessment.

A free, healthcare-specific assessment that produces an anonymized organizational readiness report with evidence-based remediation guidance.

See the platform

Request a platform demo.

A working walkthrough of the three-gate pipeline, the gateway, and the audit trail. We tailor it to your vertical and your stack.

Founder access

Apply to the Design Partner Program.

A small number of regulated organizations help shape Three Gates pre-GA. Preferred pricing, roadmap influence, and direct access to the founding team.