NEWHIP One Medical Necessity Agent is live on Microsoft Marketplace — the same medical-necessity reasoning running in CMS Medicare via WISeR. See the agent →
Healthcare provider in NJ submitting a Medicare PA?Provider Portal
WISeR · live since Jan 2026 · 25K+ auths cumulative
Trust · for security reviews and technology diligence

Security, deployment, and data ownership.

The single page for your security review: where your knowledge lives, what the frontier models can and cannot retain, which environments the platforms deploy into, and what leaves with you if you ever walk away. Written to be attached to a diligence packet.

01
The boundary

Reasoning is rented. Knowledge is owned. The line between them is the architecture.

Rented — above the line

Frontier reasoning that retains nothing

Frontier models reason over the Healthcare Brain and retain nothing of yours. They are swap-capable by design — multi-model by architecture, Claude-first by methodology — so no single vendor ever holds your operation hostage.

Owned — below the line

Your knowledge overlay, in the contract-lawyer sense

Your policies, precedents, and operational knowledge are captured in an exportable structure on your side of the containment boundary. Nothing becomes truth without your sign-off, and knowledge never crosses upward.

02
Deployment

From commercial cloud to fully sovereign — your perimeter, your call.

The platforms run across every deployment environment: commercial cloud, government cloud, on-premises, and fully sovereign — the same architecture at every tier, so a pilot in one environment carries to production in another. Government programs run the most restrictive shape; CMS WISeR is the reference production deployment.

Certifications & standards

The three-letter answers, first.

HIPAA

Operations built for protected health information — the same discipline productized in CPS One, the privacy operating system we sell and run on ourselves.

SOC 2 Type II

Controls audited over time, not attested once.

ISO 27001

Information security management certified to the international standard.

Attestation letters and audit reports available under NDA through your account team.

Audited where it counts: in production, by CMS.

Under the CMS WISeR Innovation Model — live since January 2026 in New Jersey production Medicare (MAC JL, Novitas) — the platform’s decisions are not self-reported. They are audited.

12,609
PA cases — Q1 2026, CMS-audited
genzeon.metric.wiser_cases_q1
100%
CMS three-day turnaround compliance
genzeon.metric.wiser_tat
<3 min
median decision latency
genzeon.metric.wiser_latency
0
auto-denials — by architecture, not policy
genzeon.metric.wiser_auto_denials
All the proof →
03
Governance

We sell the guardrails — and we run them on ourselves.

CPS One is a complete privacy operating system plus AI Readiness, AI Risk, and AI policy enforcement — and it is the governance layer we operate internally. Most of CPS One uses no AI, by design: the guardrails for AI should not themselves depend on it.

Questions security teams ask first

The diligence FAQ.

Do frontier models train on our data?

No. Frontier reasoning is rented and swap-capable — the models retain nothing of yours. The architecture is multi-model by design, Claude-first by methodology, and everything you teach the platform lives on your side of the containment boundary.

What happens to our knowledge if we leave?

Your knowledge overlay is owned in the full contract-lawyer sense: your policies, precedents, and operational knowledge are captured in an exportable structure, and if you ever leave, it leaves with you.

Can the Healthcare Brain run inside our perimeter?

Yes. Deployment spans commercial cloud, government cloud, on-premises, and fully sovereign environments. CMS WISeR is the reference production deployment.

Which certifications do you hold?

HIPAA, SOC 2 Type II, and ISO 27001. Attestation letters and audit reports are available under NDA through your account team.

Has any of this been audited in production?

Yes. Under the CMS WISeR Innovation Model, 12,609 prior-authorization cases were processed in Q1 2026 and CMS-audited, with 100% three-day turnaround compliance and zero auto-denials — approve-only by architecture.

Bring us your security review →