Platform
A governed desktop, built from code.
The four pillars
Secure by design
Linux desktops built for DISA STIG profiles and OpenSCAP scanning, and mapped to HIPAA technical safeguards. Compliance evidence is versioned alongside the code.
- Next: baseline hardening applied at image build time, not after deployment
- Next: every image scanned against its profile before promotion
- Findings, exceptions, and fixes tracked in version control (live: signed commits and a public changelog)
- Controls mapped to the HIPAA Security Rule technical safeguards (draft)
DISA STIGOpenSCAPHIPAA mappingAI that stays inside the boundary
Planned: local models and agents run inside your environment, so no patient data leaves the regulated boundary. Local GPU inference already runs in the build lab; the clinical agents are not built yet.
- Models served on your own hardware or private cloud
- Agents will read data only through governed FHIR access
- No prompts or patient data sent to third-party AI services
- Every agent action to be recorded in the audit trail
Local inferenceNo external callsLoggedDelivered anywhere, through the browser
Desktops reach users through a browser with single sign-on and MFA. No desktop is ever exposed directly to the internet.
- No client software to install on clinical endpoints
- Live: single sign-on with group-based desktop assignment
- WebAuthn and FIDO2 security keys next, for phishing resistance
- Remote desktop protocols stay on the private network
Browser accessSSOMFAReproducible and auditable
The goal: every desktop a versioned, rollback-capable image built from code. Today the desktop is rebuilt from versioned scripts with a full changelog; the Terraform and Ansible automation is the next phase.
- Next: desktops defined declaratively and built in a pipeline
- Live: every change is a signed commit; tagged, signed releases come with the pipeline
- Rollback by VM snapshot today; by image once the pipeline exists
- Planned: identical rebuilds across test, staging, and production
Image-basedVersionedRollback
Architecture
Four layers, one boundary.
- Access
- Browser
- TLS at the Cloudflare edge
- Guacamole gateway
- Keycloak SSO + MFA
- Workspace
- Clinical profile
- Research profile
- Admin profile
- Platform services
- Local AI runtime
- Governed knowledge base
- FHIR client
- Messaging
- Files
- Audit log
- Infrastructure
- Enterprise Linux
- Virtualization
- Kubernetes
- Private or sovereign cloud
Desktop profiles
The right desktop for each role.
- Clinical
Pharmacists, nurses, physicians
- Browser-based EHR access
- Clinical AI agents
- Unit dashboards
- Secure messaging
- Documents
- Research
Data scientists, researchers
- Python, R, and Jupyter
- Local model serving
- De-identified datasets
- Shared notebooks
- Admin
Managers, operations, IT
- Email and calendar
- Office documents
- Reporting dashboards
- Messaging and video
Image-based delivery
Ship desktops like software. Roll back like software.
Define
Desktop, packages, and hardening declared in version control.
Build
A pipeline builds the image from source, identically every time.
Scan
OpenSCAP checks the image against its hardening profile.
Promote
Signed images move from test to staging to production.
Roll back
Any prior image can be restored if a release misbehaves.