Skip to content

Platform

A governed desktop, built from code.

LocumView is being built as a complete clinical workspace defined as code: hardened operating system, curated applications, local AI, and secure delivery. Live today: secure browser delivery of a RHEL 10 desktop, versioned with a full changelog. Next: rebuild-from-code automation and hardening.

The four pillars

  • Secure by design

    Linux desktops built for DISA STIG profiles and OpenSCAP scanning, and mapped to HIPAA technical safeguards. Compliance evidence is versioned alongside the code.

    • Next: baseline hardening applied at image build time, not after deployment
    • Next: every image scanned against its profile before promotion
    • Findings, exceptions, and fixes tracked in version control (live: signed commits and a public changelog)
    • Controls mapped to the HIPAA Security Rule technical safeguards (draft)
    DISA STIGOpenSCAPHIPAA mapping
  • AI that stays inside the boundary

    Planned: local models and agents run inside your environment, so no patient data leaves the regulated boundary. Local GPU inference already runs in the build lab; the clinical agents are not built yet.

    • Models served on your own hardware or private cloud
    • Agents will read data only through governed FHIR access
    • No prompts or patient data sent to third-party AI services
    • Every agent action to be recorded in the audit trail
    Local inferenceNo external callsLogged
  • Delivered anywhere, through the browser

    Desktops reach users through a browser with single sign-on and MFA. No desktop is ever exposed directly to the internet.

    • No client software to install on clinical endpoints
    • Live: single sign-on with group-based desktop assignment
    • WebAuthn and FIDO2 security keys next, for phishing resistance
    • Remote desktop protocols stay on the private network
    Browser accessSSOMFA
  • Reproducible and auditable

    The goal: every desktop a versioned, rollback-capable image built from code. Today the desktop is rebuilt from versioned scripts with a full changelog; the Terraform and Ansible automation is the next phase.

    • Next: desktops defined declaratively and built in a pipeline
    • Live: every change is a signed commit; tagged, signed releases come with the pipeline
    • Rollback by VM snapshot today; by image once the pipeline exists
    • Planned: identical rebuilds across test, staging, and production
    Image-basedVersionedRollback

Architecture

Four layers, one boundary.

The target architecture: each layer independently versioned and tested, with patient data inside the regulated boundary at every layer. Live today: the access layer and one desktop profile.
Regulated boundary
  1. Access
    • Browser
    • TLS at the Cloudflare edge
    • Guacamole gateway
    • Keycloak SSO + MFA
  2. Workspace
    • Clinical profile
    • Research profile
    • Admin profile
  3. Platform services
    • Local AI runtime
    • Governed knowledge base
    • FHIR client
    • Messaging
    • Files
    • Audit log
  4. Infrastructure
    • Enterprise Linux
    • Virtualization
    • Kubernetes
    • Private or sovereign cloud

Desktop profiles

The right desktop for each role.

Planned: profiles assigned at sign-in based on role, each with only the applications and data access that role needs. Today there is one standard desktop plus an isolated guest desktop, assigned by group.
  • Clinical

    Pharmacists, nurses, physicians

    • Browser-based EHR access
    • Clinical AI agents
    • Unit dashboards
    • Secure messaging
    • Documents
  • Research

    Data scientists, researchers

    • Python, R, and Jupyter
    • Local model serving
    • De-identified datasets
    • Shared notebooks
  • Admin

    Managers, operations, IT

    • Email and calendar
    • Office documents
    • Reporting dashboards
    • Messaging and video

Image-based delivery

Ship desktops like software. Roll back like software.

Planned: desktops as immutable images built in a pipeline, with changes moving forward through testing and any release able to roll back. This is the next phase of the build.
  1. Define

    Desktop, packages, and hardening declared in version control.

  2. Build

    A pipeline builds the image from source, identically every time.

  3. Scan

    OpenSCAP checks the image against its hardening profile.

  4. Promote

    Signed images move from test to staging to production.

  5. Roll back

    Any prior image can be restored if a release misbehaves.