Sovereign AI Gateway · Healthcare

Nothing crosses
unseen.

Heimdall is the control layer between every healthcare application and every AI model it calls. It decides which model answers, in which jurisdiction, under which policy, and keeps the record a regulator can read without a translation layer.

Bifrost is the bridge.
Heimdall decides who crosses.

Request access See how it routes
Exhibit 01 One endpoint in front of every model
CLINICAL APPLICATIONS PACS · enterprise imaging viewer · worklist · RIS context Reporting · dictation draft · summarise · structure Digital pathology case synthesis · QA heimdall.run(task_class, payload) the app never names a model Heimdall SOVEREIGN AI GATEWAY · IN-REGION 01 Classify verify task & data class · detect PHI at the gate 02 Govern residency · model allowlist · budget · fail-closed 03 Route cheapest compliant supply, compliance outweighs cost 04 Account one immutable record · metering · evidence Bifrost · sovereign inference 3verest-owned GPU · weights never leave the tenancy DE-ID GATE Frontier model · in-region pseudonymised payload only · pinned version · ZDR Human review, the hard 5% consultant queue, by policy, not by failure THE LEDGER one immutable, hash-chained record per request, across every pool. Both sides of the contract read the same rows. classify · decide · route · prove
Certified once → every region. The application never names a model; the gate decides at request time, by task class and jurisdiction.
The problem nobody is pricing

Every health system is now running AI traffic it cannot fully account for.

A clinician summarises a discharge note and the tokens leave the country. A vendor embeds a frontier model and the data-processing agreement says, in effect, trust us. AI gateways exist, and they are multiplying, but they route on two questions: which model is cheapest, and which is fastest.

Healthcare has a third question. It is the one that ends careers when answered badly:

Where did the
data go?

Routing on cost is a procurement feature. Routing on jurisdiction is a governance requirement. No gateway on the market treats it as the primary axis. Heimdall does.

How it routes, in order

Three questions, asked in the only order that is safe.

Residency is not a region toggle. It is the routing logic itself, resolved before anything else, every time.

01
Sovereignty first

Answered inside the border, or not at all.

Every request carries a jurisdiction policy. A query from a Berlin hospital is answered inside German borders by an approved model, or it is refused. When the policy engine cannot be evaluated, identifiable data does not move. Fail-closed is the default, not the exception.

02
Capability second

The right model for the task, inside the sovereign envelope.

A frontier model for genuine reasoning. An owned model on Bifrost for clinical workloads that can never leave the tenancy. A small, fast model for the 80% of traffic that does not need a cathedral. The model is chosen at request time, by task class and depth, never hard-coded into the application.

03
Cost third

Table stakes, never allowed to overrule the first two.

Failover, caching, token-level metering, hard spend controls: the gateway category's table stakes, present and accounted for. The router seeks the cheapest compliant supply, and the weighting is deliberate. Compliance trumps cost, every time.

Every decision is logged: which model, which jurisdiction, which policy, which path. The audit trail is the product as much as the routing is.

The tier model

Sovereignty is a spectrum. The policy says so out loud.

Heimdall does not pretend that residency equals sovereignty. It names each tier honestly, records the choice in the ledger, and lets the customer's signed policy decide what is permitted for which class of data.

How the gate decides
Tier 01 · Sovereign

Owned weights, owned metal, zero external calls.

Bifrost GPU capacity inside the tenancy. A target ~70% of traffic, at utilisation economics. Pinned for the life of an OEM certification.

Tier 02 · Resident

Frontier reasoning, in-region, behind the gate.

A frontier model in the customer's jurisdiction, reached only with a pseudonymised payload. Residency ≠ sovereignty, and the policy says which the customer chose.

Tier 03 · Open

Non-clinical work, by signed exception.

Open pools, only for classes a tenant's signed policy explicitly permits, anonymisation-grade by default. The human review queue, the hard 5%, sits alongside as a supply rung, not a residency tier.

Engineering targets · 12 months post-GA
<60ms
Gateway added latency, p99
99.95%
Data-plane availability per region
≥65%
Traffic on sovereign supply
±6%
Underwriting variance, routine classes

Targets from the functional specification, not measured production figures. Live numbers, named pilot, supported models, jurisdictions at GA, published at launch. No placeholders survive to print.

Who it's for
01

Health-system CIOs

Who suspect, correctly, that AI usage in their organisation is larger and leakier than reported, and need an answer they can hand to a regulator.

02

Imaging & informatics OEMs

Embedding AI into PACS, reporting and pathology, who need a sovereignty answer their hospital customers will actually accept at contract.

03

Every 3verest tenant

For whom Heimdall ships as the default front door to AI, sovereignty controls and a full audit trail from day one, in front of the models they already use.

The honest contract

Compliance as exhaust.

One record per request, across every pool, append-only, hash-chained, in-jurisdiction. It powers metering, simulation and the evidence pack a compliance officer hands to a regulator. Both sides of every contract read the same rows. That is what makes the contracts honest.

Sovereignty & compliance
09:41:07Z report.draft.ct-chest   3v-rad-32b@2.3.1  SOV-UK/LHR
          in 6,214 (3,090 cached) · out 482 · 1.74s · per-study
09:52:33Z priors.synthesise.onc   frontier@pinned   RES-UK
          11 calls · in 48,910 · out 6,240 · 41.2s · geo:UK · ZDR
09:53:14Z escalation.consultant   human            QUEUE
          confidence 0.71 < 0.80 · playbook:onc.synth.v3 · queued
The missing layer

The AI stack has a missing layer.

Today a PACS calls a frontier API; a pathology viewer calls a cloud model. Nothing sits between the request and the model, no policy, no jurisdiction, no meter, no record. That direct line is where the risk lives.

01

Unbounded token cost

Inference is a variable cost inside a fixed-price product. Margin erodes silently, invoice by invoice.

02

Sovereignty failure

A request leaves the jurisdiction the moment it hits a foreign endpoint. Procurement finds it before the regulator does.

03

Compliance risk

The EU AI Act and its successors demand logging, traceability and oversight evidence. A direct API call produces none.

04

Model lock-in

Wire an app to one vendor's endpoint and the model becomes load-bearing. Switching means re-validation, so nobody switches.

05

Version drift

The model you validated at version X silently becomes X+1. In a clinical workflow that is a safety event, with no record it happened.

06

No auditability

When the regulator, board or buyer asks what the AI did, there is no answer. The decisions happened; nothing recorded them.

Six failures, one root cause: nobody owns the layer between the application and the model. Heimdall is that layer.

A new category · Sovereign AI Routing

Applications declare intent. Heimdall determines execution.

A radiologist's viewer does not ask for a named model in a named region. It declares a task, draft this report, and a data class. Heimdall resolves the rest: the policy that applies, the jurisdiction that binds it, the cheapest compliant model that can serve it, and the immutable record that proves it happened the way it was meant to.

Definition

Sovereign AI Routing (n.) the infrastructure layer that classifies, governs, routes and accounts for every AI request between an application and the models that serve it, under the legal authority of a chosen jurisdiction.

One gate, every healthcare AI journey

Healthcare AI OEM

Ship AI inside a fixed-price product without shipping an unbounded cost. Per-study economics, sovereignty controls and the audit trail procurement will ask for.

viewer.report.draft → classify → UK policy → owned specialist → £/study → ledger

Healthcare provider

Govern every AI request that leaves your estate, across every vendor, under one policy, one ledger, one evidence pack. Control what you already bought.

any-AI-call → classify → trust policy → approved model → budget → evidence

Digital pathology

Gigapixel slides, heavy inference, strict residency. Route per-region analysis to in-country models, price per slice, prove every read stayed onshore.

slide.region.analyse → classify → DE policy → in-region model → per-slice → ledger

Radiology

Draft reports and summarise priors at validated, version-pinned quality, with the model frozen for the certification lifetime, not silently upgraded mid-workflow.

report.draft / priors.summarise → policy → cheapest-compliant → per-study

Clinical documentation

Ambient and structured documentation over identifiable data, kept sovereign by default, metered per encounter, recorded for every note.

note.ambient.draft → classify (PHI) → sovereign model → budget → ledger

AI agent infrastructure

Give autonomous agents a governed substrate. Every tool call and model step classified, permitted, budgeted and recorded, agency without blind spots.

agent.step → classify → policy → resolve → envelope → ledger (per step)

Why 3verest

Built by the company already operating sovereign healthcare infrastructure.

Sovereign AI Routing is not a feature a generalist bolts on. It requires owning the compute, knowing the regulation, and already standing inside the healthcare estate. 3verest does.

Healthcare-only focus

Every line of the platform is built for one industry. Clinical reality is the design brief, not a retrofit.

Global sovereign cloud

A sovereign footprint across the UK, Europe, Australia, the US and Canada. Heimdall routes to capacity 3verest owns, not rents.

Bifrost sovereign AI

Owned, in-region inference behind the gate. Version stability for a certification lifetime needs owned weights and hardware.

Deep regulatory expertise

The EU AI Act, UK GDPR and NHS frameworks, the Australian Privacy Act, encoded as routing logic, not bolted on as disclaimers.

Existing OEM ecosystem

Already co-selling with the imaging and clinical-systems vendors whose AI Heimdall governs. In place, not aspirational.

Heimdall · by 3verest

Heimdall sees every model. Heimdall chooses the path.

Deploy in front of the frontier models you already use, and gain sovereignty controls and a full audit trail immediately. Bifrost is already standing behind the gate.

Email the team Read the architecture